Forum Discussion
Kerberos 401 authentication with form fallback
I don't immediately see how it's possible to tell if a PC is able to authenticate without asking it via a 401, which produces a browser auth pop-up. Is there anything in the initial HTTP request that you can use to tell this class of clients from the other class of clients?
Well, perhaps you could use Group-Policy IEM tool to modify the User-Agent and show the 401 to only those guys via some simple VPE logic? But they would have to use only IE, unless there is some way to do this with Firefox to a group of PCs.
https://technet.microsoft.com/en-us/library/cc770379.aspx
I have been trying to set this up but IE and Chrome on none domain pc's always prompt for credentials.
If I change the javascript to alert() I see it runs after the authentication popup so not sure how this will work?
If I cancel the authentication popup then the policy follows the fallback to the logon page but this won't be acceptable.
Any ideas on pre logon checks to run when source ip will not be an option?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com