Dear Community,
As part of our preparation for the upcoming product release, we are currently reviewing the authentication mechanisms used for integrations.
In previous versions, our platform used Apache HTTP Client 4 for SOAP (CXF) and REST (Jersey) communications, which provided support for NTLM authentication.
With newer versions of CXF and Jersey, Apache HTTP Client 4 is no longer the preferred option, and Apache HTTP Client 5 should be used instead. However, the latest Apache HTTP Client 5.6 releases no longer provide NTLM support. While older 5.2 versions still support NTLM, their long-term maintenance and security update strategy is unclear.
In addition, Microsoft recommends that applications move away from NTLM and adopt more modern authentication mechanisms where possible.
To help us assess the impact of a potential upgrade, we would appreciate your feedback:
- Are you currently using NTLM authentication for any REST or SOAP service integrations with the Axon Ivy platform?
- If yes, could you briefly describe the affected integration scenario and whether a migration to another authentication method would be feasible?
We would appreciate your response by 26 June 2026.
Thank you for your support.
Kind regards,
Axon Ivy Product Team