Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-73829

NTLM Negotiate Flags property is not editable in Instance Settings



      Steps to Reproduce:

      1. Configure an Active Directory and NTLM server (do not change the default Negotiate Flags in your NTLM server);
      2. Start Liferay and go to Control Panel > Instance Settings;
      3. In fieldset Configuration > Authentication:
      4. Go to General tab and change the "How do users authenticate?" field to "By Screen Name" and Save;
      5. Go to LDAP tab and add an Active Directory LDAP Server (make sure that the token for Authentication Search Filter is @[email protected]);
      6. Under the same LDAP tab, check Enabled for LDAP authentication;
      7. Go to NTLM tab and fill all the fields with the corresponding values in your NTLM server and Save;
      8. Go to Control Panel > System Settings > Foundation > NTLM and fill the Negotiate Flags with 0x211AAAAA that's different than the default value in your NTLM server and Save;
      9. Now, in a Windows environment configured to the NTLM and AD server as authentication tool, using Microsoft Internet Explorer, access the Liferay instance just configured and try to sign in.

      Actual Behavior:
      Liferay signs in succesfully with the user that's logged in the Windows environment.

      Expected Behavior:
      Since the Negotiate Flags were changed in System Settings to be different than the NTLM server, the authentication process shouldn't have been successful, and the following message should have been thrown in the app server console instead: "Session key negotiation failed".

      The reason why this is happening is because the Instance Settings is saving a blank value for that property even though it doesn't exist in the page yet.

      Reproduced on:
      master @ commit 12e1d4fdc3327c93274ded6d6b66835ce86a3cbe
      ee-7.0.x @ commit 0ee01aeb02db2a6b2a43515345475b7c711dffd3

      Not able to reproduce in 6.2.x because this property was set in portal.properties back then and all NTLM settings done inside the Portal were by Instance.




            raven.song Raven Song
            rodrigo.paulino Rodrigo Paulino
            Participants of an Issue:
            Recent user:
            Csaba Turcsan
            0 Vote for this issue
            0 Start watching this issue


              Days since last comment:
              4 years, 9 weeks, 3 days ago


                Version Package
                7.0.0 DXP FP30
                7.0.4 CE GA5
                7.1.0 Beta 3