整合式 Windows 驗證 Negotiate Kerberos NTLM 也可以只用 NTLM ,但不能只用 Kerberos 兩者都不支援 Web Proxy 要求 首先試試 接下來再試
15.
整合式 Windows 驗證 MetaBase 屬性 : AuthNTLM 如果同時啓用基本驗證和 整合式 Windows 驗證, Internet Explorer 會使用 整合式 Windows 驗證 NTAuthenticationProviders 屬性 : Negotiate,NTLM NTLM NTAuthenticationProviders 沒有任何管理介面,必須使用 adsutil.vbs 工具或 Metabase Explorer 來修改
Kerberos 用戶端 : Internet Explorer 伺服端 : IIS Server (Active Directory 網域成員 ) Active Directory: Key Distribution Center (KDC) Ticket Granting Service: 負責發出所有的 tickets (aka tokens)
Login Page <button onclick ="javascript:return infocardlogin.submit();"> Sign in with your Information Card </ button > < form name ="infocardlogin" target ="_self" method ="post"> < object type ="application/x-informationcard" name ="xmlToken"> < param name ="tokenType" value ="urn:oasis:names:tc:SAML:1.0:assertion" > < param name ="issuer" value ="http://schemas..../identity/issuer/self" > < param name ="requiredClaims" value ="http://.../claims/givenname, http://.../claims/surname, http://../claims/emailaddress, http://.../claims/privatepersonalidentifier" > </ object > </ form > public partial class Login_aspx : System.Web.UI. Page { protected void Page_Load( object sender, EventArgs e) { string xmlToken = Request[ "xmlToken" ]; Token token = new TokenProcessor . Token (xmlToken); // Lookup the account using the uniqueId string username = MembershipHelper .GetUser(token.UniqueID); if (username != null ) { MembershipUser user = Membership .GetUser(username); // give the cookie back to the browser FormsAuthentication .SetLoginCookie(user.UserName, false ); } } }
#2 <SLIDETITLE INCLUDE=7>Windows Server 2008 應用程式相容性 </SLIDETITLE> <KEYWORDS></KEYWORDS> <KEYMESSAGE></KEYMESSAGE> <SLIDEBUILDS>0</SLIDEBUILDS> <SLIDESCRIPT> Hello and Welcome to this Microsoft TechNet session on {insert session title}. My name is {insert name} </SLIDESCRIPT> <SLIDETRANSITION> <TRANSITION LENGTH=7>Let us start this session by going into more detail on exactly what we will be covering.</TRANSITION> </SLIDETRANSITION> <COMMENT></COMMENT> <ADDITIONALINFORMATION> <ITEM></ITEM> </ADDITIONALINFORMATION>