30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Specific settings and troubleshooting<br />

The login dialog is displayed only if NTLM authentication fails (e.g. when user account<br />

for user authenticated at the client host does not exist in <strong>Kerio</strong> Control).<br />

Warning:<br />

One reason of a NTLM authentication failure can be invalid login username or<br />

password saved in the Password Manager in Windows operating systems (Control<br />

Panels → User Accounts → Advanced → Password Manager) applying to<br />

the corresponding server (i.e. the <strong>Kerio</strong> Control host). In such a case, Internet<br />

Explorer sends saved login data instead of NTLM authentication of the user<br />

currently logged in. Should any problems regarding NTLM authentication arise, it<br />

is recommended to remove all usernames/passwords for the server where <strong>Kerio</strong><br />

Control is installed from the Password Manager.<br />

Firefox/SeaMonkey<br />

The browser displays the login dialog. For security reasons, automatic user<br />

authentication is not used by default in the browser. This behavior of the browser can be<br />

changed by modification of configuration parameters — see below.<br />

If authentication fails and direct connection is applied, the firewall’s login page is opened<br />

automatically (refer to chapter 12.2). The login dialog is displayed if proxy server is used.<br />

Note: If NTLM authentication fails by any reason, details are recorded in the error log (see<br />

chapter 22.8).<br />

Firefox/SeaMonkey configuration<br />

Configuration can be changed to enable automatic NTLM authentication — leaving out the<br />

login dialog. Check the following example:<br />

1. Insert about:config in the browser’s address bar. The list of configuration parameters is<br />

displayed.<br />

2. Set corresponding configuration parameter(s) using the following instructions:<br />

• For direct connection (proxy server is not set in the browser):<br />

Look up the network.automatic-ntlm-auth.trusted-uris parameter. Use<br />

the <strong>Kerio</strong> Control host’s name as a value for this parameter (e.g. server or<br />

server.company.com). This name must match the server name set under Configuration<br />

→ Advanced Options → Web Interface (see chapter 12.1).<br />

Note: It is not possible to use IP address as a value in this parameter!<br />

• If <strong>Kerio</strong> Control proxy server is used:<br />

Look up the network.automatic-ntlm-auth.allow-proxies parameter and set<br />

its value to true.<br />

Configuration changes are applied right away, i.e. it is not necessary to restart the browser.<br />

368

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!