, . , Kerberos (Negotiate), NTLM, , Windows, IIS, . A, - B, , C, .
-. B, C.
Kerberos - . -, , . , , . , Kerberos , . , , . Kerberos .
, , myApp.intranet URL-. AD SPN, , , myUser MyDomain (setspn -S MyDomain\myUser HTTP/myapp.intranet). KDN (. kerberos KDN), , myUser, IIS . SPN (HTTP/myapp.intranet), KRB.
, IIS 7+, ApplicationHost.config, ( ): useAppPoolCredentials= true. \system.webServer\security\authentication\windowsAuthentication. , auth , , .
... "" AD. , .
, SPN . , , , . DNS, , , , . :
- DNS A, .
- CName, A
- , CName , , .
, SPN NetBIOS, HTTP/machine, HOST- ( ) HTTP, HOST/machine. .
, NTLM Kerberos, ApplicationHost, SetSPN. NTLM , , , , ( NTLM). . , , , NTLM.
, . Kerberos, WireShark . , Kerberos :
- Kerberos -
- AD Kerberos ( )
- Kerberos
- Kerberos