473,396 Members | 1,933 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,396 software developers and data experts.

Authorization NTLM and PHP

Hello

Does anyone ever made full authorization via NTLM using PHP?
I tried to do it but i stucked in validating nt_hash and lm_hash
received in messageType3.
I couldn't find any example of source code how to validate them.

I also tried to use mod_ntlm for apache2 but in error log I found only that:

....
send_ntlm_challenge: no conn. handle...trouble communicating with
PDC/BDC? returning internal server error

I checked the IP connectivity from the Apache host to the PDC is OK
presumably and the httpd.conf looks like this:

# used DOMAIN, pdc, bdc are here for example

AuthType NTLM
NTLMAuth on
NTLMAuthoritative on
NTLMDomain DOMAIN
NTLMServer pdc.my.domain.com
NTLMBackup bdc.my.domain.com
Require valid-user

LoadModule ntlm_module modules/mod_ntlm.so

Has anyone similar problem?

--
Lech Wilczyński
Jul 17 '05 #1
2 13854
Hello,

On 11/14/2004 05:21 PM, Lech Wilczyński wrote:
Does anyone ever made full authorization via NTLM using PHP?
Yes, but currently only for protocol client. Server side implementation
is planned. If you would like to submit server side implementation
driver for this SASL package, it would be welcomed too.

http://www.phpclasses.org/sasl

I tried to do it but i stucked in validating nt_hash and lm_hash
received in messageType3.
I couldn't find any example of source code how to validate them.
I have not looked into this in depth yet, but I think you validate it
just by forwarding back and forth to a domain controller, instead of
trying to check it yourself.

I also tried to use mod_ntlm for apache2 but in error log I found only
that:

...
send_ntlm_challenge: no conn. handle...trouble communicating with
PDC/BDC? returning internal server error

I checked the IP connectivity from the Apache host to the PDC is OK
presumably and the httpd.conf looks like this:

# used DOMAIN, pdc, bdc are here for example

AuthType NTLM
NTLMAuth on
NTLMAuthoritative on
NTLMDomain DOMAIN
NTLMServer pdc.my.domain.com
NTLMBackup bdc.my.domain.com
Require valid-user

LoadModule ntlm_module modules/mod_ntlm.so

Has anyone similar problem?


Have you tried using explicit IP addresses for the domain controllers?

--

Regards,
Manuel Lemos

PHP Classes - Free ready to use OOP components written in PHP
http://www.phpclasses.org/

PHP Reviews - Reviews of PHP books and other products
http://www.phpclasses.org/reviews/

Metastorage - Data object relational mapping layer generator
http://www.meta-language.net/metastorage.html
Jul 17 '05 #2
Lech Wilczy?ski <me****@poczta.onet.pl> wrote:
LoadModule ntlm_module modules/mod_ntlm.so


What version of mod_ntlm are you using?
There is a rewritten version at <URL:http://source.grep.no/>.
Works great.

--
Morten Dreier
http://morten.dreier.no/
Jul 17 '05 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
by: Bruce Lewis | last post by:
I've gotten NTLM authentication working with PHP 5.0.2 and IIS 5.0, so long as I use Internet Explorer 6.0.2800. Using IE 6.0.2900 authentication doesn't happen. IE displays a "Cannot find Server...
1
by: Alper OZGUR | last post by:
hi; in our company we use NT domain with NTLM. i have an asp login page for an app that will work in our intranet. but i couldn't find any resource for checking the username and password given in...
4
by: looping | last post by:
Hi, I have to make internet connections through an ISA proxy server that use NTLM or Kerberos authorization method. I've found a program in python called ntlmaps that act like a proxy and could...
1
by: robert | last post by:
In a DAV scheme with PROPFIND or GET (PROPFIND /test/ HTTP/1.1) and Basic AUTH to a MS SharePoint over https server (AUTH required), he responds 'WWW-Authenticate: NTLM' only: reply: 'HTTP/1.1...
3
by: George Vasiliou | last post by:
Hi to all, I have made up a small client / server application with WinSock (port 443) at VB6. I have install server in my Home, and client is running behind a proxy server. Client cannot...
40
by: webrod | last post by:
Dear All, let's say I have a web service. I would like to authenticate users who try to access it. I am on a winnt server so I will have to use NTLM but I don't want to use IIS settings. Is...
2
by: Tommaso Caldarola | last post by:
I have a custom object host on IIS, windows authentication enabled. The problem raises when the remote object, invoked by the client, tries to connect to SQL Server, I get 401 error...
1
by: pycraze | last post by:
Hi , I am working on NTLM (Windows NT Lan Manager )APS (Authentication Proxy Server ) , to port to C language . I am using ethereal to monitor the packets sent between client and server ....
2
by: =?Utf-8?B?TGVuc3Rlcg==?= | last post by:
A C# (.NET 2) application which uses the System.Net.HttpWebRequest object to request a resource over HTTPS is failing following the installation of a new proxy server on our internal network with...
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.