Pros:
- Faster performance is experienced when using Kerberos as it caches information about the client after authentication. This means that it can perform better than NTLM particularly in large farm environments
- Delegation - Kerberos can delegate the client credentials from the SharePoint front-end web server to other back-end servers like Oracle. So you are eliminating double hops. (Login Challenges)
- You can also with MOSS 2007 utilize RSS feeds "Within your SharePoint Environment"
- Microsoft recommends to "Use Kerberos authentication for sites with a high security service level agreement."
- Federated Search between Farms (e.g., will work based as the user credentials are passed automatically.)
- Planning on utilizing BDC some LOB Applications will require Kerberos authentication.
- SQL Serer Reporting Services integration works well with Kerberos.
- Switch back to NTLM is possible.
Cons:
- In Active Directory, SPN should be configured carefully .If not troubleshooting is difficult
Related Links:
http://technet.microsoft.com/en-us/library/cc288475.aspx
http://ablog.apress.com/?p=1127
No comments:
Post a Comment