Acutis Gate logo Acutis Gate Health check help

Health check › Sign-in

NTLM (older PCs and apps)

Check id signin.ntlm

What it checks

Only when NTLM is turned on: checks that a domain controller can verify NTLM answers for Gate, and that relay protection can read the certificate browsers see.

What you might see

InfoNTLM is off: only Kerberos sign-in.PCs that open Gate by IP address, or old apps, will be refused.
ProblemNTLM is on but this server's secure channel to the domain is not working.Windows edition: the server's trust with the domain is broken.
ProblemNTLM is on but Gate's domain trust is not working (winbind not running).Linux appliance: Gate's computer-account join needs renewing.
CheckNTLM on with relay protection OFF.Works, but less safe.

How to fix it

Windows Server:

Command line (as an administrator)

nltest /sc_verify:CORP
Test-ComputerSecureChannel -Repair -Credential CORP\admin

Linux appliance:

  1. Identity → Active Directory, enter the service account password, Save: Gate re-joins as its computer account.
  2. If relay protection cannot read the certificate, check GATE_TLS_CERT_FILE points at the certificate your HTTPS proxy serves (the installer sets this).
  1. To turn relay protection back on: Identity → Active Directory, NTLM options. Each NTLM sign-in is marked in the audit trail, so you can see who still needs it.

Related checks

Windows sign-in (Kerberos)

Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides