Re: NTLM for extranet users?

From: Cyriel van 't End (nospam_at_anywhere.net)
Date: 10/08/04


Date: Fri, 08 Oct 2004 21:33:52 +0200

vamsi wrote:
> Can NTLM auth. pass through the firewall? I wish to use
> the same WSS server farm for both internal users and
> external partners.
>
> Does any one had success with NTLM over firewall???

Why not go the easy way and use Basic Authentication (and SSL if you
want to secure this a bit) using another virtual server which you map to
the site still using NTLM authentication?

You can do this by creating a new site in IIS, and follow the same steps
you would take in the Sharepoint Admin console to create a new site. But
instead of extending a virtual server, choose extend and map to another
virtual server. On this new virtual server turn off Windows
Authentication and enable Basic Authentication and use this site for
your external partners.

The company I work for do this all the time for our own purposes and
when implementing Sharepoint at customers... it works like a charm.

Regards,

Cyriel



Relevant Pages

  • Re: Integrated Windows Authentication Timeout?
    ... Do you see anything different for the NTLM requests? ... You might consider enabling protocol transition authentication since you are ... Joe Kaplan-MS MVP Directory Services Programming ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: (New Subject): How to eliminate prompt for credentials when using RPC over HTTP
    ... > If it worked with basic authentication, did you remember to change the ... > configuration in Outlook to use NTLM and SSL? ... > To see if it's a certificate issue, go to RWW or OWA (using your server's ... > server to avoid the security alert. ...
    (microsoft.public.windows.server.sbs)
  • Re: Integrated Windows Authentication Timeout?
    ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: "The page cannot be displayed" for non domain users
    ... The Wfetch utility is able to get true. ... The first atemp returns the page I get in the IE. ... When I use IE I never get the NTLM authentication window: ... Server: Microsoft-IIS/6.0\r\n ...
    (microsoft.public.inetserver.iis.security)
  • Re: Can we use public IP?
    ... you've set it to use Basic authentication, not NTLM, as NTLM ... Your FE server is Exchange 2003, ...
    (microsoft.public.exchange.admin)