RE: ASP.net app with Windows authentication challenging one user only

From: Chris Mohan (ChrisMohan_at_discussions.microsoft.com)
Date: 11/12/04

  • Next message: Chris Mohan: "RE: Site Config Question"
    Date: Thu, 11 Nov 2004 16:54:02 -0800
    
    

    I had to trouble shoot a similar problem last week.

    Is this user accessing the network via VPN? In my company all browsers have
    the urls of our intranet apps listed in the "Trusted Site's Zone" list of
    sites in internet explorer AND this zone is set to automatically pass thier
    workstation login information to sites in the trusted zone(not a good idea if
    people start listing arbitrary sites-- we might have actually done this for
    the "Local Intranet" zone.)

    Anyway.. after alot of troubleshooting with the user over the phone here's
    the pattern i observed.

    If the user initiates a VPN session before attempting to access the site
    then (whether or not the VPN session is active at that particular moment then
    the user is not challeged for her credentials and automatically gains access
    to the iste.)

    HOWEVER, if the user attempts to access the site BEFORE initiating the VPN
    session.. then the authentication dialog box launches. This user logins to
    her laptop using her network account.

    My "reading" of that is: initiating a VPN session must set some kind of
    authentication token on the client machine that persists throughout the
    workstation logon session. If VPN hasn't "talked" to the network prior to an
    attempt to access an internal resource then the credentials don't get
    passed(or arent' recognized as valid.. or something.)

    Hope that helps

    "Tom Ketter" wrote:

    > Hi All,
    >
    > I have an intranet application that uses ASP.net Windows
    > authentication. It has been working flawlessly for the past year.
    > Recently, one employee has experienced a problem accessing the site.
    >
    > *When the user first re-starts his computer and connects to the site,
    > it recognizes him and functions normally.
    >
    > *If he closes the browser and attempts to re-connect, it will present
    > the authentication dialog.
    >
    > *Currently, no other users are experiencing this problem.
    >
    > *It surfaced when this user began using a new computer.
    >
    > Any ideas would be greatly appreciated!
    >
    > Thanks,
    > Tom
    >


  • Next message: Chris Mohan: "RE: Site Config Question"

    Relevant Pages

    • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
      ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
      (Full-Disclosure)
    • TidBITS#792/15-Aug-05
      ... We also note the release of Security Update 2005-007, ... Macintosh FTP client, free for educational and charitable use. ... mentioned virtual private network (VPN) technologies. ...
      (comp.sys.mac.digest)
    • RE: VPN Error 800
      ... The VPN client IP is 10.0.1.40, this is a private IP address. ... server IP address is 81.137.105.244, this is a Internet IP address. ... not test VPN connection from your perimeter network. ... SBS on your switch to make it work. ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN with SBS 2003 (not R2) and DSL.
      ... Reading property value for VPN returned OK ... Reading VPN Server Name returned OK ... identical network cards. ... it seems doubtful that SBS will work properly with two NICs ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN unable to browse - access denied
      ... I do not receive a prompt for secondary windows authentication to this ... Authenticating against VPN just connects you to the network. ... With the SBS domain "guest" accounts disabled, ...
      (microsoft.public.windows.server.sbs)