File:  [NetBSD Developer Wiki] / wikisrc / kerberos / web_browser.mdwn
Revision 1.6: download - view: text, annotated - select for diffs
Wed Nov 11 21:26:48 2009 UTC (13 years, 2 months ago) by wiki
Branches: MAIN
CVS tags: HEAD
web commit by jym: Comment about MS IE Kerberos support.

First, Kerberize your [[system]]. Then:

#### [[!toggle id="firefox" text="Firefox"]]
[[!toggleable id="firefox" text="""
7. Open Firefox.
7. Go to [about:config](about:config).
7. Filter for `network.negotiate-auth`.
7. Set `network.negotiate-auth.trusted-uris` and
`network.negotiate-auth.delegation-uris` to ``.
7. **(Windows only)** Filter for `use-sspi`, then set `network.auth.use-sspi` to `false`.

#### [[!toggle id="konqueror" text="Konqueror"]]
[[!toggleable id="konqueror" text="""
Possibly the same as [[!toggle id="safari" text="Safari"]]?

#### [[!toggle id="safari" text="Safari (Mac OS X)"]]
[[!toggleable id="safari" text="""
7. Open Safari.
7. There is no Step 2.

#### [[!toggle id="ie" text="Internet Explorer"]]
[[!toggleable id="ie" text="""
Internet Explorer can use Microsoft's built-in Kerberos. Anyone know how? Some possibly relevant links:

> Sadly, it seems MS IE can only use tickets cached inside LSA (Local Security Authority), and this cache is only created upon logon through winlogon service. Which means that a `host/<windows_machine>` principal would be needed for each Windows client that wants to cache a TGT. This is only suitable for Intranet-like networks. Maybe there is another way to manage the LSA after login, similar to [[!template id=man name=kinit section=1]]... --[[jym]]

* <>
* <>
* <>
* <>

CVSweb for NetBSD wikisrc <> software: FreeBSD-CVSweb