Artemis 0 Newbie Poster

Integrated Windows Security

I had a few questions on IWS and was hoping someone knows a little about it. My client is a custom app (not IE or a different browser). All client and server components are on Windows operating systems and using Kerberos.

The first question is does IWS authenticate each message using kerberos (or NTLM) or does it set up a session? (my question is for scalability/efficiency concerns).

Second is a more general question...if the proposed app is being developed on an all Windows network and not intented for the internet, is there any advantage to using custom authentication (ws-security and https) instead of IWS?

Thanks for any responses.