Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
11.07.2015 Views

Chapter 25NTLM authentication settingsNTLM (NT LAN Manager) is an authentication type used on Windows for authentication againstan Active Directory (or NT) domain.First, the following conditions must be met:• NTLM authentication can be used only in case users are authenticated against an ActiveDirectory domain. It is applicable only to the user accounts that were imported from ActiveDirectory (see chapters 7.6 and 13.10).• In order for the NTLM authentication to be functional, both computers as well as useraccounts have to belong to the domains used for authentication.• To make NTLM relevant it is necessary that users use clients with support for NTLM (SPA)authentication (e.g. MS Outlook).Warning: NTLM authentication is not available if MS Outlook extended by the Kerio SynchronizationPlug-in is used.NTLM authentication in Kerio MailServer must be set correctly, as follows:1. In the administration console, go to Domains (Configuration → Domains). Open the dialogwith domain settings details and switch to the Advanced tab (see figure 25.1). Use theWindows NT Domain entry to specify NT domain name (the name usually matches theActive Directory domain name without the first level domain — NET, COM, etc.).2. In the administration console, go to Configuration → Advanced Options and enable theAllow NTLM authentication for users with Kerberos authentication (for Active Directoryusers) option on the Security Policy tab. Enable this option to allow Active Directory domainusers to authenticate at Kerio MailServer upon their logon.284

Figure 25.1Setting Windows NT domain nameFigure 25.2Enabling the Allow NTLM authentication for users with Kerberos authentication option3. In the administration console, open the Domain Settings → User Accounts section and setthe Windows NT Domain option for user authentication. These parameters can be set onthe General tab (see figure 25.3).285

Chapter 25NTLM authentication settingsNTLM (NT LAN Manager) is an authentication type used on Windows for authentication againstan Active Directory (or NT) domain.First, the following conditions must be met:• NTLM authentication can be used only in case users are authenticated against an ActiveDirectory domain. It is applicable only to the user accounts that were imported from ActiveDirectory (see chapters 7.6 and 13.10).• In order for the NTLM authentication to be functional, both computers as well as useraccounts have to belong to the domains used for authentication.• To make NTLM relevant it is necessary that users use clients with support for NTLM (SPA)authentication (e.g. MS Outlook).Warning: NTLM authentication is not available if MS Outlook extended by the <strong>Kerio</strong> SynchronizationPlug-in is used.NTLM authentication in <strong>Kerio</strong> MailServer must be set correctly, as follows:1. In the administration console, go to Domains (Configuration → Domains). Open the dialogwith domain settings details and switch to the Advanced tab (see figure 25.1). Use theWindows NT Domain entry to specify NT domain name (the name usually matches theActive Directory domain name without the first level domain — NET, COM, etc.).2. In the administration console, go to Configuration → Advanced Options and enable theAllow NTLM authentication for users with Kerberos authentication (for Active Directoryusers) option on the Security Policy tab. Enable this option to allow Active Directory domainusers to authenticate at <strong>Kerio</strong> MailServer upon their logon.284

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!