raZorTT
Jan 12, 2018Cirrostratus
APM - proxy NTLMv1 client side auth to NTLMv2 server side
Hi,
I've been asked if the F5 can proxy a request between a client that supports NTLMv1 and a server that currently supports NTLMv2.
My understanding of the NTLMv2 SSO Configuration is that it expects the client password to be known, and it uses that in combination with the username and domain to generate the NTLM token to be sent to the server.
Can the F5 pull the password out of an NTLM token sent by the client? I had a look at a session dump of an NTLM authenticated client side connection, but couldn't see a session variable for it.
I suspect my options are:
- Set the password using a variable assign in the access profile (client connecting is using a service account so the password doesn't change) but that's not ideal
- See if the server can be configured to support Kerberos and then setup a kerberos SSO configuration to authenticate server side
Appreciate any thoughts or suggestions
Cheers, Simon