I always considere NTLM and Kerberos to be very similar, so I am surprised to hear that NTLM is broken.
Kerberos and HTTP/2 work just fine together.
What in particular is broken with NTLM?
Kerberos and HTTP/2 work just fine together.
What in particular is broken with NTLM?
But MS has also the "Negotiate" protocol they made to replace NTLM on IE (because even the IE team considered it irremediably broken). That one is a variant of Kerberos, and a lot of people say just NTLM when they mean "Negotiate with a possible downgrade to NTLM".
https://docs.microsoft.com/en-us/iis/get-started/whats-new-i...
I’m not sure that it’s a problem with HTTP/2 that Microsoft found no reason to implement Windows authentication for it.