cancel
Showing results for 
Search instead for 
Did you mean: 

CIFS Authentication with AD login and NTLMv2

ldapuser
Champ in-the-making
Champ in-the-making
Hello,

how I can configure that Alfresco should ignore this notice?

"Only NTLM v1 is supported in this configuration. As NTLMv2 has been designed to avoid "man-in-the-middle" attacks, it would be impossible to use in this pass through style."
<strong>Source:</strong> https://docs.alfresco.com/community/concepts/auth-passthru-intro.html

I need the Active Directory users for the CIFS Share login.
But I've readed that its not possible because there could be an man-in-the-middle attack.

Is it possible through other things than pass-through?

I wouldn't touch the policies.
A workaround would be to say windows that they should send NTLM v1 instead only v2.
2 REPLIES 2

mrogers
Star Contributor
Star Contributor
Either you have to use NTLMV1  - there's a windows registry setting you need to change.
Or the other work around is to run the windows domain controller on the same windows machine as alfresco.

The real solution to this mess is not to use NTLM at all.    The current advice from Microsoft is to use kerberos instead. 

kimberlydeborah
Champ in-the-making
Champ in-the-making


You can manage CIFS authentication services from further versions. The recommended methods to configure, manage, and modify CIFS properties and parameters are by using manager.