Answer the question
In order to leave comments, you need to log in
How to make seamless authorization on a corporate website?
Good afternoon!
The following problem occurred while creating a corporate site. It is necessary to implement seamless authorization so that the user enters his login password when loading Windows, and after that he is automatically considered authorized on the site.
Answer the question
In order to leave comments, you need to log in
There are 2 options:
1. In the forehead: NTLM authorization. To work in IE/Chrome, it is necessary that the site be added to the trusted ones, in the user authentication settings there should be automatic login to the network with the current name, + additionally in windows 7+ www.symantec.com/business/support/index?page=conte ... + developers.de/blogs/damir_dobric/archive/2009/08/1... and superuser.com/questions/682524/how-to-change-local...
FF also needs sivel.net/2007 /05/firefox-ntlm-sso
Next on the site through NTLM we get the username and domain - and then, depending on the paranoia, we either take our word for it, or go to AD and check that such a user exists.
I want to emphasize separately that this method of authorization is NOT RECOMMENDED officially, because it is quite full of holes (the ntlm format on the client side is very simple, you can easily fake requests and transfer any data).
2. Use active directory federation services
I have no live experience here, but in general it looks more reliable.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question