Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[proposed enhancement] Option to suppress NTLM (forceNegotiate)? #114

Open
fusscreme opened this issue Oct 16, 2021 · 2 comments
Open

[proposed enhancement] Option to suppress NTLM (forceNegotiate)? #114

fusscreme opened this issue Oct 16, 2021 · 2 comments

Comments

@fusscreme
Copy link

fusscreme commented Oct 16, 2021

Hi,

Is there a possibility to suppress NTLM authentification and to only use Negotiate (Kerberos)? If someone brings their own device I cannot force a group policy object (GPO) to list the url in the intranet zone whitelist. And then they get this ugly popup in the browser, asking for credentials.
Therefore a option forceNegotiate just like forceNTLM would be useful.

Thank you.

@jlguenego
Copy link
Owner

jlguenego commented Oct 18, 2021 via email

@jg76379
Copy link

jg76379 commented May 24, 2022

I think this would be a good feature. node-sspi allows you to specify which SSPI packages to use with an array

sspiPackagesUsed:
default to ['NTLM']. An array of SSPI packages used. To obtain a list of all SSPI packages available on your server, download source code of mod-auth-sspi, then run bin\sspikgs.exe from your server's DOS console.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants