Posted by zdzisio on 11/09/07 05:02
Gordon Burditt:
>> I have a funny feeling
>> that you just don't have an idea what this NTLM thing is, do you?
>
> A browser can't be trusted for anything involving HTTP server
> security.
the thing is - it is not about *http* security. its not a *browser*
thing. it is about windows(smb) *workstation* authenticating against
windows (smb) server. and http server being able to know that it
happened thanks to ntlm authentication module
> I have a feeling that either
> (b) Windows provides some
> other mechanism for the HTTP server to identify the user making the
> request that doesn't involve trusting the browser.
see? it involves third party - a windows server. thats why you need this
additional module for.
z.
Navigation:
[Reply to this message]
|