[KB7241] Resolve the intranet single sign-on authentication issues with TLS filtering activated

Issue

Details


Click to expand

This situation can occur if the authentication is based on protocols such as SPNEGO (WWW-Authenticate: Negotiate), Kerberos, and NTLM, and if Channel Binding Tokens are used.

This behavior is a security feature of the underlying authentication protocol.


Solution

Create an exception on the affected computers to resolve the issue

  1. Open the main program window of your ESET Windows application.

  2. Press the F5 key to access Advanced setup.

  3. Click Protections → SSL/TLS → Edit (next to Certificate rules).

  4. Click Add.

  5. Click URL, and type the server's domain name in the URL address field. Click OK.

  6. Next to Scan action, select Ignore, then click OK.

  7. Click OK → OK to confirm the configuration change.

If you manage ESET endpoint applications remotely using ESET PROTECT, apply these settings as a policy.


Disable the "Extended Protection for Authentication" feature on the server

Disabling this feature will leave your server vulnerable to Man in the Middle attacks and is not recommended. We recommend that you attempt the solution above.

For more information, see: