---
title: "Advanced configuration for NTLM/Kerberos EasySSO"
canonical: "https://www.techtime-initiative.com/space/EasySSO/4096160/Advanced%20configuration%20for%20NTLM%2FKerberos%20EasySSO"
format: markdown
---
Users authenticated via Kerberos or NTLM (NTLMv2) Single Sign-On (SSO) based on the current domain workstation session, no login screen - no passwords asked.

> ⚠️ All options in the advanced menu have standard values. You don't need to change any of these values if you're not sure.

## Advanced options

### Enable Kerberos authentication

We suggest to get NTLM working successfully before enabling Kerberos authentication. Why? Kerberos is notoriously fickle, and in many scenarios doesn't work by design. NTLM works where Kerberos doesn't. It makes sense to get NTLM working before proceeding to configure Kerberos.

For those brave souls who want to enable Kerberos authentication, read these articles in our [FAQ](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/1638405):

1. [I have NTLM working, how do I enable Kerberos support?](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/1474702)
2. [How can I determine if a client is doing NTLM or Kerberos?](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/1474611)
3. [NTLM works but with Kerberos I am getting "Encryption type AES256 is not supported" errors in the log](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/1966142)
4. [NTLM works but with Kerberos I am getting "Mechanism level: Checksum failed" errors in the log?](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/3244304)

### Enable Log4J logging

This redirects the Jespa logs to the standard error stream. In practice this will typically be `catalina.out`. We generally recommend to initially leave this unchecked until you have everything configured and working.

### Log

set the log file location 

### Logging level

Set the logging detail level. Recommended log level for testing is 4 - this will display requests and responses, DNS queries as well as details of communication with Domain Controllers. For production use levels 1 or 2 is recommended.

### AD Site

Consult with your Domain Administrator if use of "AD Site" is necessary. 

#### What is an AD Site

Nowadays organisations often use multiple redundant Domain Controllers. They are often organised in groups known as "sites". While an End User workstation may be capable of "seeing" all Domain Controllers and connect to all of them for the sake of disaster recovery, a server often is only able to connect to the closest site (probably co-located in the same datacenter). Your Domain Administrator should be able to identify the name of the site EasySSO should use to discover all available Domain Controllers that are actually usable. 

Also see [how to determine existing AD Sites?](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/1474675) 

### Canonical Form

Canonical user account form depends on the format of usernames used in the Atlassian application. Please read IOPLEX Jespa Operators Manual about this. Most installations will use canonical form=2 e.g. for usernames like "johndoe".


> ℹ️ Consult with our 24x7 support if you feel you need to change any other parameters