Multiple proxy authentication prompts

When some particular sites are visited, multiple proxy authentication prompts are received. After canceling these pop-up windows the page can be finalized visited, we have observed that this issue is happening when Adobe Flash player is involved.
This has been an intermittent issue over the last months, however there is a site that can be used to reproduce the problem.
http://tv.adobe.com/watch/accessibility-adobe/preparing-indesign-files-for-accessibility/
Google chrome and IE are not affected

Hi Tylerdowner,
Thanks for your response. I should have mentioned two things, I am already using a recent firefox version (16.0.1) and these authentication prompts are for proxy user and password, these are not related with digital certificates as suggested in the first answer provided.
The problem that we are experiencing it is pretty similar to a well-known behaviour experienced in previous firefox versions. This can be replicated as follow:
0) Start firefox .
1) Open several sites in different tabs.
2) Close firefox selecting "Save and quit"
3) Start firefox again. Multiple authentication prompts (user and password) will be required.
Our current situation is pretty similar but it is happening when some sites with adobe flash player content is visited. For instance when this site is visited [[link text|http://tv.adobe.com/watch/accessibility-adobe/preparing-indesign-files-for-accessibility/ ]] multiple authentication prompts are poped-up
It seems to me (speculating) that adobe flash plugin may be sending a burst of hits through the proxy, as none of them has been previously authenticated, one username/password request is being sent to the browser one for each "hit" that was simultaneously sent through the proxy.
Thanks for your feedback.

Similar Messages

  • Why does Proxy Authentication prompt for user/pass on Win7 but not XP?

    Trying to use NTLM authentication for our proxy through Firefox 7.0.1. It works great in Windows XP - the user doesn't ever get prompted for his username or password when going to the internet. However, when using the same settings with Windows 7 machines going to the same internet sites, they always get prompted for username and password. Is there a workaround for this? Is this a bug?

    Start Firefox in <u>[[Safe Mode|Safe Mode]]</u> to check if one of the extensions (Firefox/Tools > Add-ons > Extensions) or if hardware acceleration is causing the problem.
    *Switch to the DEFAULT theme: Firefox/Tools > Add-ons > Appearance
    *Do NOT click the Reset button on the Safe Mode start window
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes

  • Multiple Proxy Users in OLT

    Hey All,
    As part of an infrastructure/gateway upgrade, I've been asked to load test using multiple proxy authentications. That is, different usernames that will require Active Directory authentication from/by the proxy before being allowed/denied their http requests.
    (Normally we'd use application-level authentication in the script via http.addAuthentication(....); )
    How can I do this with OLT?
    Per vUser would be most useful/flexible, followed by per script or by per load-agent machine.
    Or if not can someone suggest an alternative?
    Thanks & Regards,
    Neil

    I do not recall specifically, but look at the profile settings in OLT which you should give some access. First be sure to turn off "Ignore HTTP Proxy Settings" so agent ignores IE settings. There are some other HTTP header level settings, in "other" and "java agent" sections. If there is profile level access then with this method you will need to have multiple profiles for every vuser, but I do not believe multiple agent processes.
    a last resort will be to add headers with http.header and http.headers api calls to set i.e. "Proxy-Authorization" header

  • Random Mozilla Proxy Authentication (Mozilla Firefox 30.0)

    Hi All,
    We are experiencing an issue with random intermittent Mozilla Proxy Authentication prompts. We are running Mozilla firefox in a Windows domain and using a clearswift proxy server. I've tried a large number of configuration changes with Firefox but still get these annoying prompts. This obviously looks bad to our user base. We do not suffer the same issues with IE11 or Google Chrome.
    Please can anyone help before we look to remove this software and go for an alternative browser?
    Many Thanks,
    Kirk

    I've called in the big guys in to help you.
    What is your current Firefox and computer system?
    Have you had any other issues?
    While you are waiting, please check these out;
    Some added toolbar and anti-virus add-ons are known to cause
    Firefox issues. '''Disable All of them.'''
    Some problems occurs when your Internet security program was set
    to trust the previous version of Firefox, but no longer recognizes your
    updated version as trusted. Now how to fix the problem: To allow
    Firefox to connect to the Internet again;
    * Make sure your Internet security software is up-to-date (i.e. you are running the latest version).
    * Remove Firefox from your program's list of trusted or recognized programs. For detailed instructions, see
    '''[https://support.mozilla.org/en-US/kb/configure-firewalls-so-firefox-can-access-internet Configure firewalls so that Firefox can access the Internet.]''' {web link}
    '''[https://support.mozilla.org/en-US/kb/troubleshoot-firefox-issues-using-safe-mode Start Firefox in Safe Mode]''' {web link}
    While you are in safe mode;
    Type '''about:preferences#advanced'''<Enter> in the address bar.
    Under '''Advanced,''' Select '''General.'''
    Look for and turn off '''Use Hardware Acceleration'''.
    Poke around safe web sites. Are there any problems?
    Then restart.

  • Office 2013 Keeps Prompting Proxy Authentication

    I am using Microsoft Office 2013 behind company proxy. Each time I launch an office application it will keep on prompting me for proxy authentication on the following domains.
    this computer is in domain and I am login with domain username and password.
    dilip patel

    It's actually easy... go to your browser, for me it was Internet Explorer...go to Settings>>Internet
    options>>Connections>>LAN settings>>Advanced. Post the following in the space provided below where it says Do
    not use proxy...:
    officeimg.vo.msecnd.net;
    office.microsoft.com;
    odc.officeapps.live.com
    use a proper separator i.e. ; or , according to your browser needs. 
    this solution is taken from 
    https://superuser.com/questions/712226/how-to-get-rid-of-prompts-for-credentials-connecting-to-proxy-server-officeimg-v/809386#809386?newreg=e7e8c1c66efe4f8ea7790ae18c032fd0

  • Unable to open documents in Office (Word and Excel) - 3 authentication prompts followed by 'Could not open ...'

    I am getting multiple authentication prompts when I try to open or create a new .docx or .xslx document from SharePoint 2010. 
    I tried this on different machines and on different browsers (IE and Firefox) and see the same behavior. I am the site collection administrator. I see the same behavior on other sites also. Other users are also seeing the same behavior.
    If I download the document, I can open it without any issues.
    The Web Application IIS authentication settings is NTLM and Client Integration is enabled. 

    Hi shankze,
    According to your description, my understanding is that you could not open the documents because of the authentications.
    Go to IIS, make sure that the Security TokenServiceApplication pool is started.
    Please do as the followings, and compare the result:
    Add your site to the Trusted Sites Internet Zone.
    Go to Internet Options - Security - Highlight the Trusted Sites Check Mark - click on custom level - scroll to the bottom and in the user authentication section select "Automatic logon with current username and password."
    Also, you can do via group policy in DC server.
    More information, please refer to the link:
    http://www.networkadminsecrets.com/2011/08/sharepoint-2010-authentication-prompts.html
    I hope this helps.
    Thanks,
    Wendy
    Wendy Li
    TechNet Community Support

  • How to set proxy authentication using java properties at run time

    Hi All,
    How to set proxy authentication using java properties on the command line, or in Netbeans (Project => Properties
    => Run => Arguments). Below is a simple URL data extract program which works in absence of firewall:
    import java.io.*;
    import java.net.*;
    public class DnldURLWithoutUsingProxy {
       public static void main (String[] args) {
          URL u;
          InputStream is = null;
          DataInputStream dis;
          String s;
          try {
              u = new URL("http://www.yahoo.com.au/index.html");
             is = u.openStream();         // throws an IOException
             dis = new DataInputStream(new BufferedInputStream(is));
             BufferedReader br = new BufferedReader(new InputStreamReader(dis));
          String strLine;
          //Read File Line By Line
          while ((strLine = br.readLine()) != null)      {
          // Print the content on the console
              System.out.println (strLine);
          //Close the input stream
          dis.close();
          } catch (MalformedURLException mue) {
             System.out.println("Ouch - a MalformedURLException happened.");
             mue.printStackTrace();
             System.exit(1);
          } catch (IOException ioe) {
             System.out.println("Oops- an IOException happened.");
             ioe.printStackTrace();
             System.exit(1);
          } finally {
             try {
                is.close();
             } catch (IOException ioe) {
    }However, it generated the following message when run behind the firewall:
    cd C:\Documents and Settings\abc\DnldURL\build\classes
    java -cp . DnldURLWithoutUsingProxy
    Oops- an IOException happened.
    java.net.ConnectException: Connection refused
    at java.net.PlainSocketImpl.socketConnect(Native Method)
    at java.net.PlainSocketImpl.doConnect(PlainSocketImpl.java:305)
    at java.net.PlainSocketImpl.connectToAddress(PlainSocketImpl.java:171)
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:158)
    at java.net.Socket.connect(Socket.java:452)
    at java.net.Socket.connect(Socket.java:402)
    at sun.net.NetworkClient.doConnect(NetworkClient.java:139)
    at sun.net.www.http.HttpClient.openServer(HttpClient.java:402)
    at sun.net.www.http.HttpClient.openServer(HttpClient.java:618)
    at sun.net.www.http.HttpClient.<init>(HttpClient.java:306)
    at sun.net.www.http.HttpClient.<init>(HttpClient.java:267)
    at sun.net.www.http.HttpClient.New(HttpClient.java:339)
    at sun.net.www.http.HttpClient.New(HttpClient.java:320)
    at sun.net.www.http.HttpClient.New(HttpClient.java:315)
    at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:510)
    at sun.net.www.protocol.http.HttpURLConnection.connect(HttpURLConnection.java:487)
    at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:615) at java.net.URL.openStream(URL.java:913) at DnldURLWithoutUsingProxy.main(DnldURLWithoutUsingProxy.java:17)
    I have also tried the command without much luck either:
    java -cp . -Dhttp.proxyHost=wwwproxy -Dhttp.proxyPort=80 DnldURLWithoutUsingProxy
    Oops- an IOException happened.
    java.io.IOException: Server returned HTTP response code: 407 for URL: http://www.yahoo.com.au/index.html
    at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1245) at java.net.URL.openStream(URL.java:1009) at DnldURLWithoutUsingProxy.main(DnldURLWithoutUsingProxy.java:17)
    All outgoing traffic needs to use the proxy wwwproxy (alias to http://proxypac/proxy.pac) on port 80, where it will prompt for valid authentication before allowing to get through.
    There is no problem pinging www.yahoo.com from this system.
    I am running jdk1.6.0_03, Netbeans 6.0 on Windows XP platform.
    I have tried Greg Sporar's Blog on setting the JVM option in Sun Java System Application Server (GlassFish) and
    Java Control Panel - Use browser settings without success.
    Thanks,
    George

    Hi All,
    How to set proxy authentication using java properties on the command line, or in Netbeans (Project => Properties
    => Run => Arguments). Below is a simple URL data extract program which works in absence of firewall:
    import java.io.*;
    import java.net.*;
    public class DnldURLWithoutUsingProxy {
       public static void main (String[] args) {
          URL u;
          InputStream is = null;
          DataInputStream dis;
          String s;
          try {
              u = new URL("http://www.yahoo.com.au/index.html");
             is = u.openStream();         // throws an IOException
             dis = new DataInputStream(new BufferedInputStream(is));
             BufferedReader br = new BufferedReader(new InputStreamReader(dis));
          String strLine;
          //Read File Line By Line
          while ((strLine = br.readLine()) != null)      {
          // Print the content on the console
              System.out.println (strLine);
          //Close the input stream
          dis.close();
          } catch (MalformedURLException mue) {
             System.out.println("Ouch - a MalformedURLException happened.");
             mue.printStackTrace();
             System.exit(1);
          } catch (IOException ioe) {
             System.out.println("Oops- an IOException happened.");
             ioe.printStackTrace();
             System.exit(1);
          } finally {
             try {
                is.close();
             } catch (IOException ioe) {
    }However, it generated the following message when run behind the firewall:
    cd C:\Documents and Settings\abc\DnldURL\build\classes
    java -cp . DnldURLWithoutUsingProxy
    Oops- an IOException happened.
    java.net.ConnectException: Connection refused
    at java.net.PlainSocketImpl.socketConnect(Native Method)
    at java.net.PlainSocketImpl.doConnect(PlainSocketImpl.java:305)
    at java.net.PlainSocketImpl.connectToAddress(PlainSocketImpl.java:171)
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:158)
    at java.net.Socket.connect(Socket.java:452)
    at java.net.Socket.connect(Socket.java:402)
    at sun.net.NetworkClient.doConnect(NetworkClient.java:139)
    at sun.net.www.http.HttpClient.openServer(HttpClient.java:402)
    at sun.net.www.http.HttpClient.openServer(HttpClient.java:618)
    at sun.net.www.http.HttpClient.<init>(HttpClient.java:306)
    at sun.net.www.http.HttpClient.<init>(HttpClient.java:267)
    at sun.net.www.http.HttpClient.New(HttpClient.java:339)
    at sun.net.www.http.HttpClient.New(HttpClient.java:320)
    at sun.net.www.http.HttpClient.New(HttpClient.java:315)
    at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:510)
    at sun.net.www.protocol.http.HttpURLConnection.connect(HttpURLConnection.java:487)
    at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:615) at java.net.URL.openStream(URL.java:913) at DnldURLWithoutUsingProxy.main(DnldURLWithoutUsingProxy.java:17)
    I have also tried the command without much luck either:
    java -cp . -Dhttp.proxyHost=wwwproxy -Dhttp.proxyPort=80 DnldURLWithoutUsingProxy
    Oops- an IOException happened.
    java.io.IOException: Server returned HTTP response code: 407 for URL: http://www.yahoo.com.au/index.html
    at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1245) at java.net.URL.openStream(URL.java:1009) at DnldURLWithoutUsingProxy.main(DnldURLWithoutUsingProxy.java:17)
    All outgoing traffic needs to use the proxy wwwproxy (alias to http://proxypac/proxy.pac) on port 80, where it will prompt for valid authentication before allowing to get through.
    There is no problem pinging www.yahoo.com from this system.
    I am running jdk1.6.0_03, Netbeans 6.0 on Windows XP platform.
    I have tried Greg Sporar's Blog on setting the JVM option in Sun Java System Application Server (GlassFish) and
    Java Control Panel - Use browser settings without success.
    Thanks,
    George

  • Is Proxy Authenticated or not in Applet

    <p>
    Hi Everyone,
    </p>
    <p>
    I need to show proxy details to the user in an applet and I got the proxy host and port by using the JDK API and I need to check is the proxy is authenticated or not and I used the below code in the applet
    </p>
    <p>
    public boolean checkHttpAuthentication() {
    </p>
    <p>
    logger.info("Start of detecting proxy authentication settings");
    HttpURLConnection urlConnection = null;
    </p>
    <p>
    try {
    </p>
    <p>
    String host = SiteSurveyAppletConstants.HTTP_PROXY_DETECT_URL;
    </p>
    <p>
    URL url = new URL(host);
    </p>
    <p>
    urlConnection = (HttpURLConnection) url.openConnection();
    </p>
    <p>
    urlConnection.setDoInput(true);
    </p>
    <p>
    urlConnection.setDoOutput(true);
    </p>
    <p>
    urlConnection.setUseCaches(false);
    </p>
    <p>
    int statusCode = urlConnection.getResponseCode();
    </p>
    <p>
    logger.info("statusCode : " + statusCode);
    </p>
    <p>
    if(statusCode == HTTPStatusCodes.SC_PROXY_AUTHENTICATION_REQUIRED) {
    </p>
    <p>
    isProxyAuthenticated = true;
    </p>
    <p>
    </p>
    <p>
    } catch (Exception e) {
    </p>
    <p>
    System.out.print("Error occured while sending data to the server\n" + e);
    </p>
    <p>
    </p>
    <p>
    logger.info("End of detecting proxy authentication settings");
    </p>
    <p>
    return isProxyAuthenticated;
    </p>
    <p>
    </p>
    <p>
    When I access the applet a dialog box (Firefox browser dialog box) is prompting to enter the user credential and applet is loaded into the browser after entering the user credentials, but if you see the code in above snippet, it's not returning me the 407 status code, it's returning me the 200.
    </p>
    <p>
    In my application applet will first fetch the proxy settings and will do some processing (connecting to the server) and will load into the browser. So for connecting to the server I need to know whether the proxy is authenticated or not. If it is authenticated then I need to open a dialog box asking the user to enter the credentials and will use those credentials for connecting back to the server
    </p>
    <p>
    Can anyone help me what is causing the problem
    </p>
    <p>
    Thanks
    </p>

    Hi,
    MINUS does two full table scans & removes matches after whereas NOT IN does a full table scan of table 1 then for each row it searches through table two...assuming you have two proper tables e.g.:
    TABLE1: 20,000 rows in 1000 blocks
    TABLE2: 10,000 rows in 500 blocks
    Reads required for minus:
    Full scan of TABLE1 = 1000 blocks
    +
    Full scan of Table2 = 500 blocks
    = 1500 reads
    Reads required for NOT IN:
    Full scan of TABLE1 = 1000 blocks
    20,000 lookups in TABLE2 = 20,000 x (depth of index on TABLE2)
    = 21,000 at least
    So a lot more work is done with NOT IN. Taken from here. Note the gets:
    SQL> select count(*) from
      2  ( select object_id from t1
      3    minus
      4    select object_id from t2
      5  )
      6  /
      COUNT(*)
           171
    Statistics
              0  recursive calls
             24  db block gets
            136  consistent gets
             64  physical reads
              0  redo size
            380  bytes sent via SQL*Net to client
            518  bytes received via SQL*Net from client
              4  SQL*Net roundtrips to/from client
              3  sorts (memory)
              0  sorts (disk)
              1  rows processed
    SQL> select count(*) from
      2  ( select object_id from t1
      3    where object_id not in
      4    ( select object_id from t2
      5    )
      6  )
      7  /
      COUNT(*)
           171
    Statistics
              0  recursive calls
             12  db block gets
          84406  consistent gets
              0  physical reads
              0  redo size
            405  bytes sent via SQL*Net to client
            541  bytes received via SQL*Net from client
              4  SQL*Net roundtrips to/from client
              1  sorts (memory)
              0  sorts (disk)
              1  rows processedMike

  • ASA - cut through proxy authentication for RDP?

    I know how to set this up on a router (dynamic access-list - lock and key)... But, I'm having trouble understanding how to setup OUTSIDE to INSIDE cut through proxy authentication for RDP.
    OUTSIDE to INSIDE RDP is currently working.
    I have 2 servers I want RDP open for..
    [*]OUTSIDE 1.1.1.1 to INSIDE 10.10.70.100
    [*]OUTSIDE 1.1.1.2 to INSIDE 10.10.50.200
    What's required for OUTSIDE users  to authenticate on the ASA before allowing port 3389 opens? I was hoping for is a way to SSH into this ASA, login with a special user, then have the ASA add a dynamic ACE on the OUTSISE interface to open 3389 for a designated time limit. Is this possible?
    Here is my current config.
    [code]
    ASA Version 8.2(5)
    hostname ASA5505
    names
    name 10.10.0.0 LANTraffic
    name 10.10.30.0 SALES
    name 10.10.40.0 FoodServices
    name 10.10.99.0 Management
    name 10.10.20.0 Office
    name 10.10.80.0 Printshop
    name 10.10.60.0 Regional
    name 10.10.70.0 Servers
    name 10.10.50.0 ShoreTel
    name 10.10.100.0 Surveillance
    name 10.10.90.0 Wireless
    interface Ethernet0/0
    description TO INTERNET
    switchport access vlan 11
    interface Ethernet0/1
    description TO INSIDE 3560X
    switchport access vlan 10
    interface Ethernet0/2
    shutdown
    interface Ethernet0/3
    shutdown
    interface Ethernet0/4
    shutdown
    interface Ethernet0/5
    shutdown
    interface Ethernet0/6
    shutdown
    interface Ethernet0/7
    shutdown
    interface Vlan1
    no nameif
    security-level 50
    no ip address
    interface Vlan10
    description Cisco 3560x
    nameif INSIDE
    security-level 100
    ip address 10.10.1.1 255.255.255.252
    interface Vlan11
    description Internet Interface
    nameif OUTSIDE
    security-level 0
    ip address 1.1.1.1 255.255.255.224
    ftp mode passive
    clock timezone PST -8
    clock summer-time PDT recurring
    dns domain-lookup OUTSIDE
    dns server-group DefaultDNS
    name-server 8.8.8.8
    name-server 4.2.2.2
    domain-name test.local
    access-list RDP-INBOUND extended permit tcp any host 1.1.1.1 eq 3389
    access-list RDP-INBOUND extended permit tcp any host 1.1.1.2 eq 3389
    pager lines 24
    logging enable
    logging timestamp
    logging trap warnings
    logging device-id hostname
    logging host INSIDE 10.10.70.100
    mtu INSIDE 1500
    mtu OUTSIDE 1500
    ip verify reverse-path interface OUTSIDE
    icmp unreachable rate-limit 1 burst-size 1
    asdm image disk0:/asdm-645.bin
    no asdm history enable
    arp timeout 14400
    global (OUTSIDE) 1 interface
    nat (INSIDE) 1 LANTraffic 255.255.0.0
    static (INSIDE,OUTSIDE) tcp interface 3389 10.10.70.100 3389 netmask 255.255.255.255
    static (INSIDE,OUTSIDE) tcp 1.1.1.2 3389 10.10.50.200 3389 netmask 255.255.255.255
    access-group RDP-INBOUND in interface OUTSIDE
    route OUTSIDE 0.0.0.0 0.0.0.0 1.1.1.1 1
    route INSIDE LANTraffic 255.255.0.0 10.10.1.2 1
    timeout xlate 3:00:00
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    timeout floating-conn 0:00:00
    dynamic-access-policy-record DfltAccessPolicy
    aaa authentication ssh console LOCAL
    aaa authentication http console LOCAL
    http server enable
    http Management 255.255.255.0 INSIDE
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart
    crypto ipsec security-association lifetime seconds 28800
    crypto ipsec security-association lifetime kilobytes 4608000
    telnet timeout 5
    ssh 10.10.70.100 255.255.255.255 INSIDE
    ssh Management 255.255.255.0 INSIDE
    ssh 0.0.0.0 0.0.0.0 OUTSIDE
    ssh timeout 5
    ssh version 2
    console timeout 0
    threat-detection basic-threat
    threat-detection scanning-threat shun
    threat-detection statistics access-list
    threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
    webvpn
    username scott password CNjeKgq88PLZXETE encrypted privilege 15
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 512
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect ip-options
      inspect netbios
      inspect rsh
      inspect rtsp
      inspect skinny
      inspect esmtp
      inspect sqlnet
      inspect sunrpc
      inspect tftp
      inspect sip
      inspect xdmcp
    service-policy global_policy global
    prompt hostname context
    no call-home reporting anonymous
    call-home
    profile CiscoTAC-1
      no active
      destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
      destination address email [email protected]
      destination transport-method http
      subscribe-to-alert-group diagnostic
      subscribe-to-alert-group environment
      subscribe-to-alert-group inventory periodic monthly
      subscribe-to-alert-group configuration periodic monthly
      subscribe-to-alert-group telemetry periodic daily
    Cryptochecksum:1e9d278ce656f22829809f4c46b04a07
    : end
    [/code]

    You're running ASA 8.2(5). In 8.4(2) Cisco added support for what they call Identity Firewall rules. That is, you can make access-lists entries specific to users (or object groups containing users).
    There's an overview document on this posted here. It's a bit dated but I believe the only change is that Cisco is now preferring use of the more current Context Directory Agent (CDA) - a free VM they provide - vs. the deprecated AD agent (software service that runs on your DC).

  • ABAP client Proxy authentication required

    Hallo, my problem is about ABAP client Proxy authentication.
    Scenario:
    Our Dev. BW MWDCLNT600 queries “forward” a (RetailPro) database (JDBC Receiver C.Channel), by Dev. XI , in order to "drive" data extraction (realized, backward, from RetailPro to BW).
    Forward communication from BW uses a call on ABAP Client Proxy technology (I mean, a BW class implements an XI outbound Message Interface).
    Problem:
    Something changed, we don't know what or where, and since last week everytime you execute the report (F8) you are prompted for an authentication popup.
    Official manual guide is: (ABAP Proxy Generation)
    http://help.sap.com/saphelp_nw04/helpdata/en/ba/f21a403233dd5fe10000000a155106/frameset.htm
    in which you have to manage the 2 properties for credential supplying:
    com.sap.aii.applicationsystem.serviceuser.name
    com.sap.aii.applicationsystem.serviceuser.pwd
    in order to "drive" authentication to Integration Engine.
    In our scenario, ABAP report ZRTP_FLOW_CONTROL drives data extraction query, by a call to execute method
    of class: ZCO_MI_FLOW_CONTROL_OB
    which implements Outbound MI: MI_Flow_Control_OB (...all in SPROXY).
    In SXMB_ADM, XI IEngine URL is correct...
    In Exchange Profile, the 2 properties (see above) are correctly maintained (user: XIAPPLUSER, and password is OK)
    Any suggestion?
    Thanks all in advance!
    Gianluca

    Hi
    I would like to suggest you to change the password in http destination (sm59) configured to comunicate with XI and put another one using UPPER case only. Another thing to check is tx SLDAPICUST. There is a problem in this transaction (I think it is a problem, maybe it's a feature , you need to use password with UPPER there to, and you need to double save the data there (change something, click save, change another thing, click save, and will work, otherwise not). Check tx SLDCHECK to see if connection with SLD and Integration Directory are ok.
    Regards.
    Roberti

  • Proxy Authentication while Installing Dreamweaver Widget Browser (Mac)

    Hi,
    I have created the Adobe CS6 Web and Design Premium package using AAMEE 3.0. I have chosen to exclude adobe air and help. Exception folders have Adobe AIR Installer , Adobe Dreamweaver Widget browser and Adobe Help. ExceptionInfo.txt provides the list of commands to install the exceptions. While running the commands from the text file, Adobe AIR and Adobe Help works fine but Dreamweaver widget prompts for proxy authentication inspite of -slient parameter.
    I am using the below command from ExceptionInfo.txt to install Widget Browser
    Adobe AIR Installer.app/Contents/MacOS/Adobe AIR Installer -silent -eulaAccepted -programMenu WidgetBrowser.air
    Does this a common issue or do I need to change something in the command line?
    Regards,
    Karthikeyan M

    Hi Karthikeyan
    I haven't had the opportunity to confirm this with CS6 recently, but depending on the callback the air application makes, I have seen examples where using the -revocationCheck never command line flag could potentially make a difference. It would be interesting to see if it does under these specific circumstances with the widgetbrowser.
    See http://blogs.adobe.com/simplicity/2011/08/disabling-air-certificate-revocation-checks-duri ng-silent-install.html and http://helpx.adobe.com/creative-suite/kb/creative-suite-deployment-proxy-log.html for some background.
    Kind regards
    Henk

  • Exchange server 2013 proxy authentication

    Hi All,
    I wanted to know what is the recommended proxy authentication for exchange server 2013. 
    I have observed the following from different proxy authentications:
    1. Negotiate: By default, the proxy authentication is set to negotiate and uses anonymous as Log on network security(un-encrypted MAPI)
    2. Basic: It always prompts for the user credentials and uses encrypted MAPI.
    3. NTLM: Use negotiate at MAPI level by default
    Please provide me some information on different authentication mechanisms and the one which is recommended to use. 
    Thanks,
    Srinivas.

    Hi Srinivas,
    According to my knowledge, there are my views below:
    Basic authentication: If you select this authentication type, Outlook will prompt for username and password
    while attempting a connection with Exchange.
    NTLM authentication: If you select this authentication type, exchange does not prompt users for a user
    name and password. The current Windows user information on the client computer is supplied by the browser through a cryptographic exchange involving hashing with the Web server. If the authentication exchange initially fails to identify the user, the browser
    will prompt the user for a Windows user account user name and password. So, when Outlook is trying to connect to Exchange and if the machine is domain joined, there isn’t a need to provide password.
    Negotiate authentication: Enabled by default in Exchange 2013. This is a combination of Windows integrated
    authentication and Kerberos authentication. If we employ negotiate authentication, exchange will authenticate the client using NTLM authentication type and if unable to verify authenticity, will challenge the client to authenticate using a username and password.
    And you could set the authentication type like this:
    ExternalClientAuthenticationMethod : Basic
    InternalClientAuthenticationMethod : Ntlm
    IISAuthenticationMethods           : {Basic, Ntlm, Negotiate}
    The command below for your reference:
    Get-OutlookAnywhere | Set-OutlookAnywhere -InternalHostname "internalServer.contoso.com" -InternalClientAuthenticationMethod Ntlm -InternalClientsRequireSsl $true -ExternalHostname "externalServer.company.com" -ExternalClientAuthenticationMethod Basic -ExternalClientsRequireSsl $true -IISAuthenticationMethods Negotiate,NTLM,Basic
    If you have any further questions, please let me know.
    Best regards,
    Eric

  • Proxy authentication failed in MAc OS 10.8.3

    I am using firefox 21.0 in Mac os 10.8.3.We are using proxy server for browsing.While browsing internet firefox prompts for proxy username and password,after entering the correct user name and password it shows proxy authentication failed,Another round of authentication required.The same user name and pssword in working fine in safari in the same mac book.
    Plz Help

    Hi There!
    Please check the solution mentioned here:
    http://kb.globalscape.com/KnowledgebaseArticle10522.aspx
    I remember someone else also suggested setting this option '''network.automatic-ntlm-auth.allow-proxies''' to '''false '''as well.
    Hope this helps!
    Have a good one!
    Dawid

  • Why do I keeping getting proxy authentication request when trying to read Gmail?

    I am behind a Blue Coat proxy, whenever I try to hit gmail or google play, I get a pop-up that request user authentication (moz-proxy). I have seen a number of post on this and tried the fixes. Nothing seems to help. When I tried this: https://support.mozilla.org/en-US/questions/943488, Step three: network.automatic-ntlm-auth.allow-proxies – FALSE, I was block from hitting any webpage. I have tried opening is SAFE MODE, that did not work. Are there any other solutions?

    "IE’ uses windows authentication, and authenticates with proxy server silently behind the scenes. Chrome uses IE’s settings in windows, for proxy settings. Hence the same behavior as IE. But Firefox, tries to do it on its own, that is why it tries to authenticate and find out if you have access to the site.
    But, yeah, for your problem, the best way would be to ignore proxy for the site if you know they are already blocked."
    Reference: http://nasarabna.wordpress.com/2010/03/03/firefox-keeps-prompting-for-proxy-authentication/

  • Proxy authentication using SAAJ

    Hi everybody,
    Is it possible do connect from a JAXM 1.1 (JWSDP 1.0, Java XML Pack Summer 02 Bundle) client that is behind a proxy/firewall that requires user authentication ?, should I use the Apache SOAP implementation ?, ideas ?, suggestions ?
    TIA,
    Pedro Mendoza

    hi ddossot,
    thanks for your prompt reply, i have tried http.proxyUserName and http.proxyPassword (both clear-text and BASE64 encoded) but unfortunately i still receiving "407 Proxy Authentication required" error message, i have tried to connect through the same proxy using the Apache SOAP (instead of Sun SAAJ RI) and everything was right
    perhaps i am missing something, i would apreciate further help on this issue since (if we need to migrate to Apache SOAP) it would mean a serious code rewrite
    if you prefer i could provide you the code-snippet so you could figure out what is happening
    TIA,
    Pedro

Maybe you are looking for

  • I can't receive security info mail

    I can't receive security info mail from appleid. I have tried many times, but still failed ( I have checked my gmail for 10 times at least...).

  • New General Leger Acccountung Active ............................

    Hi all I activated Reconcilation Ledger in controlling at the time of system showing.yellow message ......................................................................................................................................................

  • TestStand Sequence Editor message

    When TestStand is launched, getting a popup window - 'Value must be at least 0'. What does that mean? Will it make any effect on test sequence execution?

  • Jump Menu to Images HELP...

    I am working on a site for work. Here is a link to the image swapping that I would like to do. http://www.grixeyewear.com/products/id/8 For example: When you go towards the bottom of the page and select the lens color and frame color, the sunglasses

  • Does FireFox 4 have a traditional menu bar (File, Edit, etc)?

    I was looking at the screenshot on the opening page about FF4 and it looks distressingly similar to Chrome and Opera. Does FF4 have the traditional controls available as an option? Call me old-fashioned, but I hate these new browser designs. I want a