SPNEGO-based Kerberos and NTLM HTTP Authentication in Microsoft Windows
RFC 4559, “SPNEGO-based Kerberos and NTLM HTTP Authentication in Microsoft Windows”, is an Informational document published in June 2006 by K. Jaganathan, L. Zhu, J. Brezak. The canonical text is published by the RFC Editor.
Abstract
This document describes how the Microsoft Internet Explorer (MSIE) and Internet Information Services (IIS) incorporated in Microsoft Windows 2000 use Kerberos for security enhancements of web transactions. The Hypertext Transport Protocol (HTTP) auth-scheme of "negotiate" is defined here; when the negotiation results in the selection of Kerberos, the security services of authentication and, optionally, impersonation (the IIS server assumes the windows identity of the principal that has been authenticated) are performed. This document explains how HTTP authentication utilizes the Simple and Protected GSS-API Negotiation mechanism. Details of Simple And Protected Negotiate (SPNEGO) implementation are not provided in this document. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4559 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4558 Node-ID Based Resource Reservation Protocol Hello: A Clarification Statement
- RFC 4560 Definitions of Managed Objects for Remote Ping, Traceroute, and Lookup Operations
- RFC 4557 Online Certificate Status Protocol Support for Public Key Cryptography for Initial Authentication in Kerberos
- RFC 4561 Definition of a Record Route Object Node-Id Sub-Object
- RFC 4556 Public Key Cryptography for Initial Authentication in Kerberos
- RFC 4562 MAC-Forced Forwarding: A Method for Subscriber Separation on an Ethernet Access Network
- RFC 4555 IKEv2 Mobility and Multihoming Protocol
- RFC 4563 The Key ID Information Type for the General Extension Payload in Multimedia Internet KEYing