Re: [squid-users] Performance: Negotiate or NTLM?

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Wed, 30 Mar 2011 12:45:29 +1300

 On Tue, 29 Mar 2011 15:09:20 +0200, Fran Márquez wrote:
> Hi,
>
> Is the Negotiate auth protocol faster than NTLM or it also increase
> (x2 or x3) the http traffic when is used?
>
> Regards,
> F.J

 Negotiate is a wrapper protocol, so the answer is maybe.

 In modern browsers it commonly wraps Kerberos auth. Which is more
 efficient on the handshakes, has stronger hash algorithms than NTLM and
 backend helpers avoid the 256 concurrency limit in winbind. So is worth
 trying to use either way.

 Older versions of MS software is known to wrap it around NTLM. Which
 means no gains and no real difference at all.

 If you try the migration and hit these old MS software problems Markus
 Moeller is currently developing a wrapper helper to handle both
 Negotiate/NTLM and negotiate/Kerberos.

 Amos
Received on Tue Mar 29 2011 - 23:45:33 MDT

This archive was generated by hypermail 2.2.0 : Wed Mar 30 2011 - 12:00:02 MDT