NTLM auth and Outlook Express trouble

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

NTLM auth and Outlook Express trouble

Postby dop38 » Feb 01 06 11:41 pm

Hi,
Sorry for my english :(

I'm currently evaluating WinGate 6.1.1 (1077)
I'm use NTLM auth + AD user database. Clients -- Windows XP Pro SP2.
WWW-browsing working fine, but other applications can't authorize after IE stop browsing.
For example, while user request html page, he can receive/send email (pop3, smtp) and connect through SOCKS to ICQ server.

After 10 seconds MS Outlook Express 6 can't connect to proxy -- "authentification failed"

WGIC resolve this problem, but it sometime request credentials before user logon into Windows and it conflict with RADMIN application (remote administration utility www.radmin.com)

If user connect to ICQ (or other SOCKS service) server then his authentification never break ...

1) Java auth is disabled :(
2) Assumed by computer name is not acceptable (any user on any computer)
3) Assumed by IP is not acceptable because I'm use dynamic ip's

Thank you ...
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby Pascal » Feb 02 06 10:57 am

From the sound of it you have your policies set to require authentication. NTLM auth through the web proxy will give you the required security level; but POP3, etc. will not. (Secure vs Unsecure auth)

When you close the browser the user/computer's auth status drops to "Assumed", rather than "Authenticated" and if a subsequent session for the same machine does not use an authentication scheme which will raise the security level it will be denied access.

There are several ways around this; one such is using WGIC but excluding System Applications that do not need to access the Internet. Another alternative is to use the Qbik Auth Tool to authenticate users with WinGate.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby dop38 » Feb 02 06 7:33 pm

Thank you,
But WGIC is not acceptable by several reasons
What is "Qbik Auth Tool" ?
I'm wrote C++ tool that authentificate user, connect to SOCKS and wait for disconnect, then connect again and again and again ... %)
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby Pascal » Feb 02 06 9:07 pm

I'll find a link for you; should be somewhere under our downloads. Another alternative is to use GateKeeper, but that has a larger UI footprint while the auth tool just sits in the clock window.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby Pascal » Feb 02 06 9:10 pm

Got it; download from here
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby dop38 » Feb 02 06 11:25 pm

Pascal wrote:Got it; download from here


Thank you very much ! :)
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby dop38 » Feb 07 06 1:45 am

Sorry, but i'm found unexpected bug :(
QbikAuth cannot authorize user with password in russsian letters. Just change user password to "english letters + numbers" and all works fine.

Russian keyboard layout is default. And i can't require users to switch layouts every logon to system :(

stupid users :))))

Can you help me ?
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby Pascal » Feb 07 06 9:46 am

Sure, I'll pass it on to Genie.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby genie » Feb 07 06 9:48 am

Sure - will check it now.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby dop38 » Feb 08 06 10:44 pm

Genie,
I'm use link from Pascal, but downloaded file is identical to previous version.
What's wrong ?
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby genie » Feb 08 06 11:09 pm

Hold on, the link there pointed to the old version of the file.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby dop38 » Feb 09 06 2:59 am

waiting for new version :)
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby genie » Feb 10 06 3:34 pm

Quick question: do you use NTLM-based authenctication?
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby dop38 » Feb 11 06 12:03 am

yes. NTLM only.
Users in domain.
Usernames -- latin letters only
Passwords -- latin, russian letters, digits.
History contains lines with username and clear COMPUTER and WG USER fields :(
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby genie » Feb 11 06 12:13 am

I ran the tests and it appeared that there is a problem when authentication token is being built with password in Russian - we'll do some additional research on this matter.
genie
Qbik Staff
 
Posts: 1788
Joined: Sep 30 03 10:29 am

Postby dop38 » Feb 11 06 1:53 am

thank you.
still waiting ...
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm

Postby dop38 » Mar 03 06 12:59 am

And what ?
This problem is unresolveable ?
I need to search other application for proxy ?
dop38
 
Posts: 9
Joined: Feb 01 06 11:27 pm


Return to WinGate

Who is online

Users browsing this forum: Bing [Bot] and 2 guests