Hi,
we recently enabled the "Extended Protection" security feature on our Exchange servers to defend against authentication relay and man-in-the-middle (MitM) attacks (see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410).
Since enabling this feature, SSO login (Single Sign-On) with Firefox is no longer working. Instead of automatic login, we are always prompted for Basic Authentication credentials:

With Chrome and Edge, SSO continues to work as expected.
Our assumption is that this may be due to missing support for channel binding in Firefox, or perhaps there is an unknown configuration option we missed.
Can you confirm whether this behavior in Firefox is known? Is there any configuration or planned change to support channel binding?
We would appreciate any feedback or advice you can provide.
Thank you very much and best regards,
Florian Singer
--
Landeshauptstadt München
IT-Referat
it@M
Geschäftsfeld Infrastruktur, Basisservices und Support
Stadtweite Basisanwendungen
Serviceteam Kommunikation & Kollaboration
Browser (Chrome, Edge, Firefox), VLC Media Player
--
You received this message because you are subscribed to the Google Groups "enter...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to enterprise+...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/enterprise/ecb6cff1f24e458cb825927876eeca73%40muenchen.de.
Hi,
thank you for your quick response!
We have tested with Firefox versions 140.13esr and 153.0esr.
We are using Negotiate authentication (Kerberos or NTLM, depending on the environment) for SSO with our Exchange OWA/EWS setup. In both cases, the issue occurs as soon as Extended Protection (Channel Binding) is enabled on the server.
We have seen Bug 1895277 and wanted to check with you first. If you do not have any further suggestions or ideas, we will open a new Bugzilla entry for this issue in the near future.
Thank you very much for your support!
Best regards,
Hi,
thank you for the detailed instructions.
I have performed the test as described:
Unfortunately, SSO still does not work in Firefox with Extended Protection enabled on the server.
We have now created a Bugzilla entry for this issue: https://bugzilla.mozilla.org/show_bug.cgi?id=2060492
Best regards,
Florian
--
Thank you for your detailed explanation and suggestions.
I checked which authentication methods are offered by our Exchange server using Firefox’s developer tools. The response headers for the OWA site show:
NTLM is not listed as an available authentication method.
Nevertheless, I proceeded with the test as you described:
Unfortunately, the issue remains unchanged. SSO does not work in Firefox when Extended Protection is enabled on the server.
Thank you again for your support!