简体   繁体   English

Windows Server 2008 R2 上的 Windows 身份验证 (NTLM) 对于 Sharepoint 2010 是否安全?

[英]Is Windows Authentication (NTLM) on Windows Server 2008 R2 secure for Sharepoint 2010?

Is it generally considered secure to use Windows NTLM Authentication for Sharepoint 2010 on a Windows 2008 R2 server?在 Windows 2008 R2 服务器上使用 Sharepoint 2010 的 Windows NTLM 身份验证通常被认为是安全的吗?

This Sharepoint install WILL BE exposed to the Internet.此 Sharepoint 安装将暴露在 Internet 上。
Is NTLM in 2008 R2 sent as clear text, or some otherwise easily defeat-able encryption? 2008 R2 中的 NTLM 是以明文形式发送的,还是以其他容易破解的加密形式发送的?

I want to be sure we aren't making ourselves vulnerable by this authentication method.我想确保我们不会因为这种身份验证方法而使自己容易受到攻击。

My gut says forms authentication with SSL would be best.我的直觉说,使用 SSL 进行 forms 身份验证是最好的。

Comments?注释?

Your gut is leading you in the right direction.你的直觉引导你朝着正确的方向前进。 NTLMv2 can be vulnerable to an attack known as a forwarding attack where an interloper could set up a proxy between your client and server and hijack an authenticated session. NTLMv2 可能容易受到称为转发攻击的攻击,其中入侵者可以在您的客户端和服务器之间设置代理并劫持经过身份验证的 session。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

相关问题 适用于SharePoint 2010的Windows Server 2008或2008 R2 SP1 - Windows server 2008 OR 2008 R2 SP1 for SharePoint 2010 是否可以在安装了 AD 角色的同一 Windows Server 2008 R2 机器上安装 SharePoint 2010 服务器? - Is it possible to install SharePoint 2010 Server on the same Windows Server 2008 R2 machine with AD role installed? 如何在Windows Server 2012 R2上安装Sharepoint Server - How to install sharepoint server on windows server 2012 r2 steps 将Web部件部署到Windows Server 2008 R2中 - Deploy Web Part Into windows server 2008 R2 Microsoft.ACE.OleDB.12.0 + Windows Server 2008 R2 +电子表格通过UNC路径访问SharePoint = :( - Microsoft.ACE.OleDB.12.0 + Windows Server 2008 R2 + Spreadsheet being accessed via UNC path into SharePoint = :( 如何在SQL Server 2008 R2上使用Visual Studio 2010调试SharePoint存储过程? - How to debug SharePoint stored procedures with Visual Studio 2010 on SQL Server 2008 R2? 使用 Windows 身份验证访问 R 中的共享点 - Accessing sharepoint in R with windows authentication Windows Server 2008上的SharePoint安装问题 - SharePoint Installation Problem on Windows Server 2008 将报表部件部署到SharePoint 2010集成SSRS 2008 R2实例时出现问题 - Problem Deploying Report Parts into SharePoint 2010 Integrated SSRS 2008 R2 Instance SharePoint 2010和SQL Server 2008 - SharePoint 2010 and SQL Server 2008
 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM