Tag Archives: authentication

Firefox and NTLM authentiction

I love my Firefox and it is still my no 1 browser for general browsing but one thing that really annoys me at work is that it doesn’t play nice with Integrated Windows authentication (aka NTLM) when dealing woth Intranet web applications. Fortunately there is a ‘fix’ for it that requires a tweaking the internal settings (about:config) of Firefox.

Follow these steps to enable NTLM for specific web servers:

  1. In the URL bar type about:config and accept the warning you might be getting…
  2. Look for or filter for the property ‘network.automatic-ntlm-auth.trusted-uris’
  3. Edit (double-click) this property
  4. Add the server names or addresses separated by commas. .i.e localhost,serverA,serverB,…
  5. Save changes (click OK)
  6. Open Firefox’s ‘Options’ and go to the ‘Advanced’ tab -> Network
  7. In the Connection section click ‘Settings’ and add the same server names in the ‘No Proxy for’ text box. This is to make sure it doesn’t use the proxy to access these servers which will break the NTLM authentication as well.
  8. Save any changes (click OK)

Too bad Firefox can’t automatically figure out which local ‘Intranet’ servers require NTLM authentication like IE and Chrome does…

 

 

 

 

Force IIS to use NTLM

Today I’ve learned something new/old again. I’ve been having problems with an application that is running on IIS (6) where it kept on giving the error “HTTP Error 401.1 – Unauthorized: Access” when you try to access it by the machine name e.g. http://machineName/AppName. If you use the IP address then it works fine e.g. http://ipadress/AppName.

The application must use Integrated security because it only allows certain people to access it or only some people have full read and write functionality. In the code I must identify which user is logged on so it also make use of impersonation. To make sure the application itself has access to some databases it runs under an application pool that is configured under a domain account.

After some searching I came across the following kb article:

http://support.microsoft.com/kb/871179

The second workaround turns out to solve the problem. It turns out IIS6 does not authenticate the user correctly if only Integrated security is selected (anonymous is turned of) plus the application runs under an application pool that is configured with a different account (other than local system or network).

Update: Just to simplify searching for a workaround here is a copy of the text of the KB:

Workaround

To work around this behavior if you have multiple application pools that run under different domain user accounts, you must force IIS to use NTLM as your authentication mechanism if you want to use Integrated Windows authentication only. To do this, follow these steps on the server that is running IIS:

  1. Start a command prompt.
  2. Locate and then change to the directory that contains the Adsutil.vbs file. By default, this directory is C:\Inetpub\Adminscripts.
  3. Type the following command, and then press ENTER:
    cscript adsutil.vbs set w3svc/NTAuthenticationProviders “NTLM”
  4. To verify that the NtAuthenticationProviders metabase property is set to NTLM, type the following command, and then press ENTER:
    cscript adsutil.vbs get w3svc/NTAuthenticationProviders

    The following text should be returned:

    NTAuthenticationProviders       : (STRING) "NTLM"

Of course, doing this you do at your own risk 🙂