NTLM Authentication

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

NTLM Authentication

Postby serginho » May 16 07 4:06 am

Hi,

I've successfully configured NTLM Authentication for browsing, but one issue is really annoying. I hope there is a solution for it:

We use a web-based email client for reading emails (www.desknow.com). When a message is received that contains links to internet sites, the browser opens an authentication dialog box for every link (so it seems, never counted exactly). I was able to minimize the annoyance by altering the security setting on IE to "User authentication = automatic".

I understand that there are messages that come with "hidden" links, that preferrebly shouldn't be open. But for the regular user, this is not a concern: the annoyance itself, is.

Is there a way to avoid the repeating solicitations for the authentication, so the user can press CANCEL just once (or, one can authenticate only once)? If not, is it possible to configure FireFox to automatic logon?

Follows the code (RFC822) for a message with links to images that produces the described effect.

Thanks

Code: Select all
X-DN-ReceivedFileId: 1937d.TCE4WYN2ECNM36AF235C.112901fff19.eml
X-DN-Spam-Bayesan-Probability: 0,2286
Delivered-To: serginho@zurlo.lan
Received: from spooler by zurlo.lan (Mercury/32 v4.01b); 15 May 2007 11:16:20 -0300
X-Envelope-To: <serginho@zurlo.com.br>
Return-path: <serginho@zurlo.com.br>
Received: from ZIRROUT1 (192.168.0.250) by zurlo.com.br (Mercury/32 v4.01b) with ESMTP ID MG000056;
   15 May 2007 11:16:18 -0300
Received: from internal
          by ZIRROUT1 (DeskNow) with SMTP ID 1128ed48724_3MTC_14
          for <serginho@zurlo.com.br>;
          Tue, 15 May 2007 11:16:18 -0300 (BRT)
Date: Tue, 15 May 2007 11:16:18 -0300 (BRT)
From: "Serginho (Zurlo)" <serginho@zurlo.com.br>
To: Serginho <serginho@zurlo.com.br>
Message-ID: <32475387.201179238578238.JavaMail.SYSTEM@ZIRROUT1>
Subject: teste imagens
MIME-Version: 1.0
Content-Type: multipart/alternative;
   boundary="----=_Part_27_9085805.1179238578238"
X-DN-SentFlag: OK
X-Priority: 3
X-Mailer: DeskNow 3.2.7
X-DN-AuthenticatedSender: XPTLE69FXENXJCAU3KRJR67YWFMWHACL-2HpgeumGFZgqi/sTS
  NSTLLZ36ilOdgCgD7HPJYXdgCjqP8kYi2gKGJ2AGWQHjRCy---

------=_Part_27_9085805.1179238578238
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

"











 Serginho (i9)
------=_Part_27_9085805.1179238578238
Content-Type: text/html;charset="UTF-8"
Content-Transfer-Encoding: 7bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
<META http-equiv=Content-Type content="text/html; charset=UTF-8">
<STYLE type=text/css>
<!--
.message {background: white; font-size:10pt; font-family:'Arial'; color:#000000}
 .message p { margin-top: 0em; margin-bottom: 0em; }
 -->
"</STYLE>
</HEAD>
<BODY class='message' bgColor=#ffffff>

<br /><img src="http://www.zurlo.com.br/mail/email.jpg" /><br /><div align="left"> <font color="#0000ff"> <br /><img src="http://www.inove.inf.br/Imagens/brasil1.gif" /><br /><br /><br /><img src="http://www.espumatec.com.br/portugues/img_temp/index_13.
jpg" /><br /><br /><br /><img src="http://www.gamamatrizes.com.br/portugues/images/temp/logo.jpg" /><br /><br /></font></div><hr width="100%" size="2" /><div align="center"><font color="#0000ff"><font color="#00ccff">&nbsp;</font></font><font color="#00
ccff"><font color="#0099ff">Serginho (i9)</font></font><br /></div><hr width="100%" size="2" /><div align="center"><br /></div>
</BODY></HTML>
------=_Part_27_9085805.1179238578238--
serginho
 
Posts: 23
Joined: Sep 28 05 6:33 am

Postby defeX! » May 18 07 10:37 am

You could set the authentication level in WinGate to user may be assumed rather than user must be authenticated. That way, when your clients provide their username and password once, they will remain authenticated for a short period of time in WinGate and subsequent login prompts won't appear.

Or, you could make a policy that allows everyone access to that website without authentication.

Or if you want to get tricky, you could do both. Create a policy that allows access to that website and set the authentication to "user may be assumed"
defeX!
 
Posts: 9
Joined: Feb 15 07 6:48 am


Return to WinGate

Who is online

Users browsing this forum: Bing [Bot] and 4 guests