Hello Maxim,
Many thanks for ur timely reply!
But I am still not quite understand about term "connection-based". I checked with wireshark again, even NTLM auth schema, it did not just use one socket to transport the whole data, it also uses several sockets to transfer a HTML page in parallel. So it works just like Digest Authentication, at least, in the auth process, they are the same. So I am totally stuck in here, where is the session info and how does Win NT keep them? And if what I have noticed was true, why Digest Authentication worked but not NTLM?
A lonely Nginxer in china :-)