Description
HTTP Negotiate uses SPNEGO to negotiate mechanisms such as Kerberos and can support integrated authentication in enterprise environments. It requires suitable authentication infrastructure and client support; authentication alone does not encrypt HTTP content.
Potential impact
Unsupported clients may fail to authenticate. Without HTTPS, request and response content may be exposed even after successful authentication.
Remediation
Use HTTPS and verify the authentication mechanism actually selected and the clients’ support for it. If it does not suit the intended environment, choose another method and update the server, clients, and documentation together.
Examples
These excerpts show switching from Negotiate to OAuth2 as an option. Negotiate can remain suitable for an enterprise authentication environment. Apply the actual authentication configuration as well as the schema change, and use HTTPS.
Before
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "http",
"scheme": "negotiate"
}
}
}
}
After
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"petstore_auth": {
"type": "oauth2",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://example.com/api/oauth/dialog",
"tokenUrl": "https://example.com/api/oauth/token",
"scopes": {
"read:pets": "read your pets"
}
}
}
}
}
}
}