| Author |
Message |
![[Post New]](/Sysforums/templates/default/images/icon_minipost_new.gif) 13/04/2012 17:19:59
|
CalebR
SysAider
Joined: 13/04/2012
Messages: 3
Offline
|
Greetings,
We are installing SysAid and wanted to use SSO, but the instructions state that LM authentication is required:
If SSO is still not enabled after following the above instructions, there is an additional change that must be made in the Domain Controller Security Settings for each of your computers. Open Local Policies\Security Options and then set the Network Security --> LAN Manager Authentication Level to LM and NTLM responses. Test this change on one computer, and if it works, make this change for all of your computers using a group policy.
Since using LM and the older version of NTLM creates a serious security vulnerability, I am hoping there is an alternative. NTLMv2 or Kerberos should be the only authentication protocols used.
If SysAid can use NTLMv2 so we can use the SSO feature, but if it requires the unsecure NTLM, or especially LM authentication, we cannot permit it as these protocols are trivial to compromise.
Thank you
Also see:
http://www.windowsecurity.com/articles/Protect-Weak-Authentication-Protocols-Passwords.html
http://support.microsoft.com/kb/147706
http://www.windowsecurity.com/articles/What-You-Dont-Know-Can-Hurt-You-LAN-Manager-Might-Be-Supported.html
|
|
|
![[Post New]](/Sysforums/templates/default/images/icon_minipost_new.gif) 30/04/2012 10:46:40
|
alep71
SysAider

Joined: 31/03/2011
Messages: 11
Offline
|
Hello,
in my opinion the only way you can avoid using NTLMv1 authentication in SSO is using a IIS as a frontend proxy.
Regards
|
|
|
![[Post New]](/Sysforums/templates/default/images/icon_minipost_new.gif) 15/07/2012 15:07:56
|
Shai Nissan
SysAid Customer Relations
Joined: 13/06/2011
Messages: 17
Offline
|
Hi CalebR ,
This issue require investigation.
If you still don't have a solution for this, please contact helpdesk@sysaid.com.
Thanks,
Shai
|
|
|
![[Post New]](/Sysforums/templates/default/images/icon_minipost_new.gif) 02/11/2012 20:25:15
|
raowen
SysAider

Joined: 30/12/2010
Messages: 26
Offline
|
Was there ever a fix for this? Does version 9 resolve this issue or does it still exist.
|
|
|
![[Post New]](/Sysforums/templates/default/images/icon_minipost_new.gif) 07/11/2012 12:51:56
|
Lior
SysAid R&D

Joined: 03/01/2008
Messages: 191
Offline
|
Kerberos SSO was added in 9.0.
|
|
|