Review HTTP Negotiate authentication (OpenAPI 3.0)

Check environment compatibility and transport protection for Negotiate

Description

HTTP Negotiate uses SPNEGO to negotiate mechanisms such as Kerberos and can support integrated authentication in enterprise environments. It requires suitable authentication infrastructure and client support; authentication alone does not encrypt HTTP content.

Potential impact

Unsupported clients may fail to authenticate. Without HTTPS, request and response content may be exposed even after successful authentication.

Remediation

Use HTTPS and verify the authentication mechanism actually selected and the clients’ support for it. If it does not suit the intended environment, choose another method and update the server, clients, and documentation together.

Examples

These excerpts show switching from Negotiate to OAuth2 as an option. Negotiate can remain suitable for an enterprise authentication environment. Apply the actual authentication configuration as well as the schema change, and use HTTPS.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "http",
        "scheme": "negotiate"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/api/oauth/dialog",
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References