Поиск в Поддержке

Избегайте мошенников, выдающих себя за службу поддержки. Мы никогда не попросим вас позвонить, отправить текстовое сообщение или поделиться личной информацией. Сообщайте о подозрительной активности, используя функцию «Пожаловаться».

Подробнее

Kerberos authentication working for Chrome, Edge, Opera, and Brave, but not Firefox

  • 3 ответа
  • 1 имеет эту проблему
  • Последний ответ от Mike Kaply

more options

Firefox (129.0.2) displays "401 - Unauthorized: Access is denied due to invalid credentials" (see attached image)

I have tried various combinations of setting and not setting the following in Firefox:

  • network.negotiate-auth.trusted-uris
  • network.negotiate-auth.delegation-uris
  • network.auth.use-sspi

For the URI settings I have tried both .domainname.domainextension and https://servicename.domainname.domainextension

In Windows 10 Control Panel -> Internet Options, the site is in "Trusted sites" using a domain wildcard, and also "Local intranet" and both "Automatic logon" and "Enable Integrated Windows Authentication" are enabled. I suspect those setting aren't relevant since other browsers are authenticating without error or prompt, but calling this out to show that I've covered that base.

The web service is served by IIS 10.0 on Windows Server 2022 and the authentication provider list only includes Negotiate, but I don't believe this issue has anything to do with IIS or its configuration as, again, other browsers are authenticating without error or prompt.

Anything else to check?

Thank you for any guidance you can offer.

Firefox (129.0.2) displays "401 - Unauthorized: Access is denied due to invalid credentials" (see attached image) I have tried various combinations of setting and not setting the following in Firefox: * network.negotiate-auth.trusted-uris * network.negotiate-auth.delegation-uris * network.auth.use-sspi For the URI settings I have tried both .domainname.domainextension and https://servicename.domainname.domainextension In Windows 10 Control Panel -> Internet Options, the site is in "Trusted sites" using a domain wildcard, and also "Local intranet" and both "Automatic logon" and "Enable Integrated Windows Authentication" are enabled. I suspect those setting aren't relevant since other browsers are authenticating without error or prompt, but calling this out to show that I've covered that base. The web service is served by IIS 10.0 on Windows Server 2022 and the authentication provider list only includes Negotiate, but I don't believe this issue has anything to do with IIS or its configuration as, again, other browsers are authenticating without error or prompt. Anything else to check? Thank you for any guidance you can offer.
Приложенные скриншоты

Изменено bryan

Все ответы (3)

more options

Here's some documentation on this:

https://htmlpreview.github.io/?https://github.com/mdn/archived-content/blob/main/files/en-us/mozilla/integrated_authentication/raw.html

that hopefully helps.

If that doesn't work, let me know. Might be easiest to open a bugzilla bug and get developers involved.

Полезно?

more options

Mike Kaply said

Here's some documentation on this: https://htmlpreview.github.io/?https://github.com/mdn/archived-content/blob/main/files/en-us/mozilla/integrated_authentication/raw.html that hopefully helps. If that doesn't work, let me know. Might be easiest to open a bugzilla bug and get developers involved.

unfortunately there wasn't any guidance in there that hasn't already been followed from other sources

Полезно?

more options

I'm at a loss.

I think you might get some better help on this from our enterprise list.

https://groups.google.com/a/mozilla.org/g/enterprise

Most of the folks there are deploying Firefox an dealing with this stuff on a day to day basis.

If you don't get any responses there, we can open a bugzilla bug and see if we can get the networking team to take a look.

Полезно?

Задать вопрос

Для ответа на сообщения вы должны войти в свою учётную запись. Пожалуйста, задайте новый вопрос, если у вас ещё нет учётной записи.