cancel
Showing results for 
Search instead for 
Did you mean: 

NTLM Single-Sign-On Issues - lmcompatibilitylevel

javier_arias
Champ in-the-making
Champ in-the-making
We have a NTLM Single-Sign-On problem that is client dependant. Some machines are working nicely while some others don't.

Client Machines are Windows XP and 2003 Srvr running InternetExplorer 6.0.29.

Our Server is Windows XP SP2 running Alfresco 2.1 on Tomcat 5.5 and Jdk 1.5.0.

We tested Alfresco 2.1.1 and 2.9.0B, with same results.

We activated NTLM debug. It seems that non-working machines are not sending correctly the password, since domain, username and workstation are correctly sent to Alfresco Server.

Set of tests executed on non-working machines:
- Upgrade IE to 7.0, no change.
- Set IE to ask for user password instead of single-sign-on, no change.
- Tried Firefox (no SSO, but asks for usr/passwd). Firefox is logging on correctly on the same machine.
- Debugging, here we found some interesting points: password length was much bigger on non-working machines, maybe it has to do with NTLM client settings?
   
In development environment, which was working correctly, changed registry setting:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\lmcompatibilitylevel
From value 0 to:
1 - Working Ok
2 - Working Ok
3 - Not working
4 - Not working
5 - Not working


Microsoft states that 3 value is forcing the client to use NTLMv2, and in our environment it fails to Authenticate.
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/76052.mspx?mfr=true

So the question is, is the NTLMAuthenticationFilter compatible with NTLMv2?

Anyway, probably in production environment we will not be able to change the lmcompatibilitylevel, so, anybody knows a good solution for this issue?
   
Thanks in advance.
2 REPLIES 2

andy
Champ on-the-rise
Champ on-the-rise
Hi

We support up to NTLMv1 - after that you have to move to Kerberos.

Andy

roman
Champ in-the-making
Champ in-the-making
Hello Andy,

please could you look at this thread?
http://forums.alfresco.com/viewtopic.php?t=11273

got problems with NTLM, is it because NTLMv2?

best regards
roman
Getting started

Tags


Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.