anonymous
Thu Oct 30 09:05:36 CST 2003
Ken,
I have set the delegation for my web server in ADUC and
Integrated Authentication is still not functioning. I
agree with using Basic & SSL (which I had instituted as a
work-around), but apparently IWA is still not working.
Thanks for your help.
Hunter
>-----Original Message-----
>I'm sorry - I don't understand when you say "you don't
have a fix".
>
>If you want to continue to use IWA in a Windows 2000
domain you need to
>allow delegation.
>If you have a Windows 2003 domain, then you have the
additional option of
>"constrained delegation"
>
>If you do not want to enable delegation (eg for security
reasons), then
>you'll need to use Basic Authentication (and I suggest
you run this over
>SSL)
>
>Cheers
>Ken
>
><phf12@mcsdk12.nospam.org> wrote in message
>news:0a9701c397e1$0d3f16a0$a601280a@phx.gbl...
>: Ken,
>:
>: I am experiencing a similar problem with a Windows 2003
>: server (IIS 6.0) in a Windows 2000 domain. I am flying
>: through the resource kit but havent found a fix yet.
Any
>: ideas on resolving the Kerberos/Integrated Auth. issue
>: here?
>:
>: Thanks!
>:
>: Hunter
>:
>:
>: >-----Original Message-----
>: >The "problem" isn't really a problem - it's expected
>: behaviour.
>: >
>: >When you use IWA, your user password is never sent
>: across the wire - that's
>: >what makes it more secure that Basic authentication.
>: However, the token that
>: >the webserver gets from the Domain Controller doesn't
>: have permission to
>: >logon to other network resources.
>: >
>: >When you use Basic authentication, your username *and*
>: password are
>: >transmitted, in the clear, to the webserver, who can
>: then "act" on your
>: >behalf (as if you were logged on at the webserver) and
>: get access to network
>: >resources
>: >
>: >(I'm sure the actual way this works is a little more
>: complex, but this
>: >should suffice for the purposes of your dilemma).
>: >
>: >OK, so what do you do about it?
>: >
>: >With Windows 2000 you need to enable delegation
(Windows
>: 2003 allows for
>: >constrained delegation which is much "safer" in that
you
>: can restrict the
>: >services that are delegated). Now, you say you have a
>: Windows 2003 native
>: >mode domain? If so, then you need to follow the
>: delegation procedure
>: >outlined in Chapter 5 ((IIRC) of the IIS 6 Resource
Kit:
>: >
>: >
http://www.microsoft.com/downloads/details.aspx?
>: displaylang=en&familyid=80A1B6E6-829E-49B7-8C02-
>: 333D9C148E69
>: >
>: >Cheers
>: >Ken
>: >
>: >
>: >"JayDee" <darius_falt@hotmail.com> wrote in message
>: >news:eEtDGi8lDHA.2268@TK2MSFTNGP12.phx.gbl...
>: >: hello again.
>: >:
>: >: Further to my last post "IIS 6 help! - Cant
>: authentication to Virtual Dir
>: >on
>: >: another machine"
>: >:
>: >: I am still struggling with this.
>: >:
>: >: It seems that when I use "integrated authentication"
>: that the credentials
>: >: parsed from my browser to the web server are not
being
>: used correctly by
>: >the
>: >: webserver to authenticate me on the target resource:
>: The target resource -
>: >: as I mentioned - is located on another machine.
>: >:
>: >: How do I know this?
>: >:
>: >: a) - I can see in the log files that the correct
>: credentials are being
>: >: parsed from my browser to the webserver.
>: >: b) - Despite the fact these credentials are being
>: parsed, i'm still being
>: >: asked to present credentials by way of the
>: browser 'Username and Password'
>: >: dialogue box.
>: >: c) - Even if I manually present valid credentails at
>: this dialogue box,
>: >I'm
>: >: still not able to authenticate to the target
resource.
>: After 3 attempts at
>: >: entering info into the Dialogue, I get the same
401.3
>: Error -
>: >"Unauthorized:
>: >: Access is denied due to an ACL set on the requested
>: resource"
>: >:
>: >: Hence - this is a general problem with the way the
web
>: server is using my
>: >: credentials to authenticate with the target
resource.
>: >:
>: >: If I change the Authentication method
>: from "Integrated" to "Basic", I am
>: >: always prompted for credentials, this is expected.
>: >: This time, if I enter valid credentials, then the
Web
>: Server give me
>: >access
>: >: to the resource I need.
>: >:
>: >: So the problem here seems to be in how the IIS6 Web
>: Server parses my
>: >: credentials for authentication on the target
resource,
>: but ONLY when its
>: >: handling it via INTEGRATED AUTHENTICATION
>: >:
>: >: I thought that it might be something to do with NTLM
>: versus Kerberos,
>: >: but this just adds to my confustion as in my test
>: instance everything
>: >should
>: >: be working with Kerberos,
>: >:
>: >: Heres the setup.
>: >:
>: >: Its a W2K3 native mode domain,
>: >: with a W2K3 Web Server and IIS 6.
>: >: The client machine is WinXP Pro SP1a
>: >: The user and computer accounts are both members of
>: this W2K3 Domain,
>: >:
>: >: I'm trying to digest the info I've found in the
>: arcticle 332142,
>: >: I'll also try manually setting the authentication
>: method by adapting the
>: >: IIS5 procedure given in 215383,
>: >:
>: >:
>: >: Bu I'm completely in the dark here. I could reall
>: really use some MS help
>: >on
>: >: this.
>: >:
>: >:
>: >: Anyone out there?
>: >:
>: >:
>: >: thanks people - I really appreciate your time.
>: >:
>: >:
>: >
>: >
>: >.
>: >
>
>
>.
>