Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Specific settings and troubleshooting General conditions The following conditions are applied to this authentication method: 1. Kerio Control Engine is running as a service or it is running under a user account with administrator rights to the Kerio Control host. 2. The server (i.e. the Kerio Control host) belongs to a corresponding Windows NT or Active Directory (Windows 2000/2003/2008) domain. 3. Client host belongs to the domain. 4. User at the client host is required to authenticate to this domain (i.e. local user accounts cannot be used for this purpose). 5. The NT domain or the Active Directory authentication method (see chapter 16.1) must be set for the corresponding user account under Kerio Control. NTLM cannot be used for users authenticated only internally inside Kerio Control. Kerio Control configuration NTLM authentication of users from web browsers must be enabled in Users → Authentication Options. User authentication should be required when attempting to access web pages, otherwise enabling NTLM authentication is meaningless. Figure 25.1 NTLM — user authentication options 366

25.3 Automatic user authentication using NTLM The configuration of the Kerio Control’s web interface must include a valid DNS name of the server on which Kerio Control is running (for details, see chapter 12.1). Figure 25.2 Kerio Control’s Web interface configuration Note: In the Software Appliance / VMware Virtual Appliance edition, the server name is set on the System Configuration tab (see chapter 17.1). Web browsers For proper functioning of NTLM, a browser must be used that supports this method. By now, the following browsers are suitable: • Internet Explorer • Firefox or SeaMonkey NTLM authentication process NTLM authentication process differs depending on a browser used. Internet Explorer NTLM authentication is performed without user’s interaction. 367

Specific settings and troubleshooting<br />

General conditions<br />

The following conditions are applied to this authentication method:<br />

1. <strong>Kerio</strong> Control Engine is running as a service or it is running under a user account with<br />

administrator rights to the <strong>Kerio</strong> Control host.<br />

2. The server (i.e. the <strong>Kerio</strong> Control host) belongs to a corresponding Windows NT or Active<br />

Directory (Windows 2000/2003/2008) domain.<br />

3. Client host belongs to the domain.<br />

4. User at the client host is required to authenticate to this domain (i.e. local user accounts<br />

cannot be used for this purpose).<br />

5. The NT domain or the Active Directory authentication method (see chapter 16.1) must<br />

be set for the corresponding user account under <strong>Kerio</strong> Control. NTLM cannot be used for<br />

users authenticated only internally inside <strong>Kerio</strong> Control.<br />

<strong>Kerio</strong> Control configuration<br />

NTLM authentication of users from web browsers must be enabled in Users → Authentication<br />

Options. User authentication should be required when attempting to access web pages,<br />

otherwise enabling NTLM authentication is meaningless.<br />

Figure 25.1<br />

NTLM — user authentication options<br />

366

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!