DisableAuthNegotiateCnameLookup

Disable CNAME lookup when negotiating Kerberos authentication

Supported on:

  • Chrome (Windows) since version 9

Description:

Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.

Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.

true = Disable CNAME lookup during Kerberos authentication
false = Use CNAME lookup during Kerberos authentication

Supported features:

  • Applied to browser without restart. Note that some ongoing tasks may not be affected.
  • Applied at Samsung Browser level, cannot be set by Cloud user policies.

Data type:

Boolean
Windows:REG_DWORD

Windows registry location:

Software\Policies\Samsung\Internet\DisableAuthNegotiateCnameLookup

Example value:

0x00000000

More policies under HTTP authentication: