Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Kerberos and NTLM

Posted on 2013-01-02
3
Medium Priority
?
658 Views
Last Modified: 2013-03-23
Hi

We are using Windows 2003 AD.

We have many different applications, and some need to authenticate to AD using either Kerberos or NTLM.

Could someone please clear a few things up for me -

i. Which one is the 'preferred' authentication mechanism - Kerboros or NTLM?

ii. MS products such as Outlook, SharePoint etc - which one do they use?

iii. If I used a product like Wireshark for example, is it possible to see which authentication mechanism was being used?

iv. Are there any benefits to using Kerberos over NTLM (or vice-versa)

v. Which one is the 'newer' protocol?

vi. Can their ports be changed?
0
Comment
Question by:redman20111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 38736233
Kerberos is preferred and default

They should be using kerberos for AD authentication

You can use a network sniffer but take a look at these two articles from the askds team...not easy to audit NTLM.  It should also help with your questions.

http://blogs.technet.com/b/askds/archive/2009/10/08/ntlm-blocking-and-you-application-analysis-and-auditing-methodologies-in-windows-7.aspx

http://blogs.technet.com/b/askds/archive/2012/03/29/3478646.aspx

Thanks

Mike
0
 

Author Comment

by:redman20111
ID: 38736700
Hello Mike

Thanks for the info...so if we had an application that used NTLM to authenticate, what are the downsides of that for us? Should we push the vendors to utilise Kerberos?

Or are there any advantages of NTLM over Kerberos?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38736841
I can't think of NTLM advantages.   Yes push vendors to use Kerberos and if they can't ask them why not.   They have had plenty of time...the blog below is from 2006

http://blogs.technet.com/b/authentication/archive/2006/04/07/ntlm-s-time-has-passed.aspx


Thanks

Mike
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question