000022425 - Is SSL a requirement for Integrated Windows Authentication (IWA)?

Document created by RSA Customer Support Employee on Jun 16, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000022425
Applies ToRSA ClearTrust Agent 4.6 for Microsoft IIS
Microsoft Internet Information Server (IIS) 6.0
Microsoft Integrated Windows Authentication (IWA)
IssueIs SSL a requirement for Integrated Windows Authentication (IWA)?
RSA ClearTrust Agent 4.6 for Microsoft Internet Information Services (IIS) Installation and Configuration Guide states "Some IWA user credentials are passed over the network in vulnerable clear text format. Components involved in IWA must be configured to use SSL connections."
CauseThis information is incorrect. RSA ClearTrust does not express the credentials in plain-text during the authentication process, and Integrated Windows Authentication (IWA) does not do this either.
ResolutionSSL is not a requirement for Integrated Windows Authentication (IWA).
Legacy Article IDa28489

Attachments

    Outcomes