Mozilla 도움말 검색

고객 지원 사기를 피하세요. 저희는 여러분께 절대로 전화를 걸거나 문자를 보내거나 개인 정보를 공유하도록 요청하지 않습니다. "악용 사례 신고"옵션을 사용하여 의심스러운 활동을 신고해 주세요.

자세히 살펴보기

Does Firefox ESR still supports NTLM v1 ?

  • 6 답장
  • 0 이 문제를 만남
  • 5 보기
  • 최종 답변자: Mike Kaply

more options

This might be a simple question. Does Firefox ESR still supports NTLM v1 ? Can we still add the value "network.negotiate-auth.delegation-uris" in preference. Does that enabled NTLM v1. Is there any document or release notes that states Firefox is disabling this setting from Firefox 78 and later. Some how I am not able to find it in release notes.

This might be a simple question. Does Firefox ESR still supports NTLM v1 ? Can we still add the value "network.negotiate-auth.delegation-uris" in preference. Does that enabled NTLM v1. Is there any document or release notes that states Firefox is disabling this setting from Firefox 78 and later. Some how I am not able to find it in release notes.

모든 댓글 (6)

more options

Are you sure you mean NTLM v1?

That hasn't been supported for 7 years.

more options

raam.bc said

Can we still add the value "network.negotiate-auth.delegation-uris" in preference.

It looks like the preference is detected in both Firefox 102esr and the latest development code (Firefox Nightly 114). I don't have a server to test on.

more options

Thanks Mike Kaply and jscher2000.

Yes Mike Kaply, I am aware that NTLM v1 is not directly supported, but as you see based jscher2000 comments "network.negotiate-auth.delegation-uris" is indirectly supporting NTLM v1. Are we able to find any release notes that states that NTLM v1 is completely not supported in Firefox.

I am asking this question for an audit documentation related with security of Firefox and want to make sure NTLM v1 is still supported or not.

more options

> "network.negotiate-auth.delegation-uris" is indirectly supporting NTLM v1.

I'm not sure why you would think that. It's just supporting NTLM.

NTLM v1 was disabled in this bug 9 years ago (Firefox 30)

https://bugzilla.mozilla.org/show_bug.cgi?id=828183

more options

Looking at that bug more, it was disabling insecure NTLM v1. I'm still researching.

more options

We support turning on NTLMv1, but we don't have it on by default.