<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NTLM Single-Sign-On Issues - lmcompatibilitylevel in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158237#M112364</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;We have a NTLM Single-Sign-On problem that is client dependant. Some machines are working nicely while some others don't.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Client Machines are Windows XP and 2003 Srvr running InternetExplorer 6.0.29. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Our Server is Windows XP SP2 running Alfresco 2.1 on Tomcat 5.5 and Jdk 1.5.0. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We tested Alfresco 2.1.1 and 2.9.0B, with same results.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We activated NTLM debug. It seems that non-working machines are not sending correctly the password, since domain, username and workstation are correctly sent to Alfresco Server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Set of tests executed on non-working machines:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Upgrade IE to 7.0, no change.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Set IE to ask for user password instead of single-sign-on, no change.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Tried Firefox (no SSO, but asks for usr/passwd). Firefox is logging on correctly on the same machine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Debugging, here we found some interesting points: password length was much bigger on non-working machines, maybe it has to do with NTLM client settings?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In development environment, which was working correctly, changed registry setting: &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\lmcompatibilitylevel&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;From value 0 to:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1 - Working Ok&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 - Working Ok&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3 - Not working&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4 - Not working&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5 - Not working&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Microsoft states that 3 value is forcing the client to use NTLMv2, and in our environment it fails to Authenticate. &lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/76052.mspx?mfr=true" rel="nofollow noopener noreferrer"&gt;http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/76052.mspx?mfr=true&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So the question is, is the NTLMAuthenticationFilter compatible with NTLMv2?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Anyway, probably in production environment we will not be able to change the lmcompatibilitylevel, so, anybody knows a good solution for this issue?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Feb 2008 11:28:10 GMT</pubDate>
    <dc:creator>javier_arias</dc:creator>
    <dc:date>2008-02-12T11:28:10Z</dc:date>
    <item>
      <title>NTLM Single-Sign-On Issues - lmcompatibilitylevel</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158237#M112364</link>
      <description>We have a NTLM Single-Sign-On problem that is client dependant. Some machines are working nicely while some others don't.Client Machines are Windows XP and 2003 Srvr running InternetExplorer 6.0.29. Our Server is Windows XP SP2 running Alfresco 2.1 on Tomcat 5.5 and Jdk 1.5.0. We tested Alfresco 2.1</description>
      <pubDate>Tue, 12 Feb 2008 11:28:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158237#M112364</guid>
      <dc:creator>javier_arias</dc:creator>
      <dc:date>2008-02-12T11:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Single-Sign-On Issues - lmcompatibilitylevel</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158238#M112365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We support up to NTLMv1 - after that you have to move to Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 12:54:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158238#M112365</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2008-02-20T12:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Single-Sign-On Issues - lmcompatibilitylevel</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158239#M112366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;please could you look at this thread?&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://forums.alfresco.com/viewtopic.php?t=11273" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/viewtopic.php?t=11273&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;got problems with NTLM, is it because NTLMv2?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;best regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;roman&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2008 16:07:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-single-sign-on-issues-lmcompatibilitylevel/m-p/158239#M112366</guid>
      <dc:creator>roman</dc:creator>
      <dc:date>2008-02-28T16:07:29Z</dc:date>
    </item>
  </channel>
</rss>

