You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@httpd.apache.org by "Roy T. Fielding" <fi...@kiwi.ICS.UCI.EDU> on 1999/11/07 03:33:07 UTC

Re: Kerberos authentication and authentication (proxy ticket forwarding)

HTTP is a stateless protocol in which no information from any prior
request is needed in order to understand the current request.  No amount
of spec lawyering will get around that basic requirement.  That is why
the NTLM authorization isn't HTTP.  I doubt this has anything to do with
kerberos authentication, provided that the mechanism is done right.

....Roy