为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Authentication using Spnego

more options

We have developed a web application which supports integrated windows authentication using spnego.

For enabling integrated authentication on Mozilla firefox i have made followin configuration

network.negotiate-auth.trusted-uris = domain of the trusted uri network.negotiate-auth.allow-non-fqdn = false network.negotiate-auth.allow-proxies = true network.negotiate-auth.using-native-gsslib = true.

My application doesnt support ntlm so havent made any configuration related to that.

Everything works file inside local network. I mean the browser is able to get kerberos service token and send it to my application.

But when I hit the same trusted site outside local network I observed that it doesnt respond at all.

Below is the flow 1. I hit the trusted url from mozilla browser outside local network 2. My application challenges browser for service token with 401 Negotiate challenge 3. Browser tries to get service token but is unable to get it because its outside the domain(Local intranet) and cannot find kerberos server or KDC. 4. Browser doesnt respond at all. I was expecting that it will respond with empty service ticket.In IE I observed that it sends NTLM token.

I want to know why the browser is not responding and how should I handle such scenario ?

We have developed a web application which supports integrated windows authentication using spnego. For enabling integrated authentication on Mozilla firefox i have made followin configuration network.negotiate-auth.trusted-uris = domain of the trusted uri network.negotiate-auth.allow-non-fqdn = false network.negotiate-auth.allow-proxies = true network.negotiate-auth.using-native-gsslib = true. My application doesnt support ntlm so havent made any configuration related to that. Everything works file inside local network. I mean the browser is able to get kerberos service token and send it to my application. But when I hit the same trusted site outside local network I observed that it doesnt respond at all. Below is the flow 1. I hit the trusted url from mozilla browser outside local network 2. My application challenges browser for service token with 401 Negotiate challenge 3. Browser tries to get service token but is unable to get it because its outside the domain(Local intranet) and cannot find kerberos server or KDC. 4. Browser doesnt respond at all. I was expecting that it will respond with empty service ticket.In IE I observed that it sends NTLM token. I want to know why the browser is not responding and how should I handle such scenario ?

所有回复 (1)

more options

Can you find anything useful in Firefox's error console? Ctrl+Shift+j to open. Typically it works best to Clear what's there and reload the page on which you want to take an action. See what errors/warnings/messages might be relevant, then submit the form/click the button that takes the non-working action and check for new errors/warnings/messages.