BLOG

KB 2786: Olfeo compatibility with different Windows authentication modes

Olfeo compatibility with different Windows authentication modes

Background1

As part of an explicit proxy integration explicit proxyintegration, Olfeo is connected to a Windows domain that includes at least one PDC (Primary Domain Controller) and possibly a second DC (Domain Controller); Olfeo attempts to perform NTLM or Kerberos authentication.

Definitions


NTLM
: NTLM (NT Lan Manager) is an authentication protocol used in various implementations of Microsoft network protocols and supported by the "NTLMSSP" (NT LM Security Support Provider). Originally used for secure authentication and negotiation, NTLM is also used throughout Microsoft systems as asingle sign-on mechanism.

Source: NT Lan Manager — Wikipedia

Kerberos : Kerberos is a network authentication protocol based on a secret key mechanism (symmetric encryption) and the use of tickets, rather than plaintext passwords, thus avoiding the risk of fraudulent interception of user passwords. Created at the Massachusetts Institute of Technology, it is named after the Greek god Cerberus, guardian of the Underworld (Κέρβερος). Kerberos was first implemented on Unix systems.

Source: Kerberos (protocol) — Wikipedia

 

Types of Windows authentication offered by Olfeo

Different types of authentication

Compatibility chart

  WS 2003 WS 2008 WS 2012 WS 2016 Winter School 2019
Olfeo v6.4 NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos
Olfeo v6.5 NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos NTLM / Kerberos