First of all: This is not an in-depth Kerberos how-to, nor is this tutorial about the different aspects of web application testing. This tutorial is just to give support in testing Kerberos authenticated web applications. The goal is to hand over the right tools and steps to be able to perform the configuration and be able to test the application.
When to use it?
When there is a 401 server response with the header “WWW-Authenticate:
Negotiate”. This can either mean Kerberos or NTLM authentication is needed. It
is possible to distinguish them by looking at valid authenticated client
traffic. As a simple reminder: The NTLM Authorization header will always start
with the value “TlRM…”, the Kerberos Authorization header will always start with
“YII…”. For further information this
link is
recommend.
In this tutorial the term “Kerberos authentication” will be used. There are
other terms sometimes used like SPNEGO, SSO or integrated authentication.