Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Testing that a website is using Kerberos authentication

Tags:

iis

kerberos

How do you go about checking that an IIS website is successfully using Kerberos and not falling back on NTLM?

like image 339
James Newton-King Avatar asked Oct 20 '25 16:10

James Newton-King


1 Answers

One way I found to test in code that you are using Kerberos is that that the HTTP_AUTHORIZATION header for NTLM always starts with the following:

Negotiate TlRMTVNTUA

If the header doesn't start with text then the browser is authenticating using Kerberos.

like image 163
James Newton-King Avatar answered Oct 24 '25 14:10

James Newton-King