integrated authentication not working from redirect

From: Danno (googlegroups@danno.mail.coppock.com)
Date: 12/20/02


From: googlegroups@danno.mail.coppock.com (Danno)
Date: 20 Dec 2002 10:46:30 -0800


I'm seeing strange auth behavior from the default IE 6, on XP Pro,
regarding HTTP redirects.

SITUATION: I configure IIS (5) on a server to require integrated
authentication (NTLM auth) for some page. I then try to access the
page from IE 6, on XP Pro.

[1] (WORKS OKAY) When the above page is accessed by the browser above,
and if the browser is in the same intranet security zone (as defined
in Internet options->Security->Local intranet->Sites), then the
Windows logon credentials are supplied, and the NTLM Automatic login
thing works great, no pop-up. The page is accessed.

[2] (WORKS OKAY) If I access cgi (also hosted in the same security
zone as the browser) that redirects (browser receives HTTP 302) to the
same site as in [1], again, all works okay. The browser sees the 302,
moves on to the NTLM-protected page, and again Automatic logon works
just fine.

[3] (FAILS) If the cgi that provides the redirect is considered to
NOT be on the same security zone (intranet) as the browser, after
moving to the protected page, the browser seems to refuse to
participate in the automatic logon process, and pops up the logon
dialog.

My question is why would IE care from where it was redirected. Is
this some new security behavior? I only see this on XP Pro. IE 6 on
NT, W2k, 98 seem to not care, and proceeds with the auto logon. Can
anyone add any clarification to what's going on here? Is there some
security thing that XP is trying to address. It's not immediately
clear how the source of the redirect is of concern. It should be
trivial to duplicate this scenario, to convince yourself of the
behavior. Any insight is greatly appreciated.

- Danno



Relevant Pages

  • Re: The Windowsupdate site redirects and fails
    ... > which immediately redirects in turn to ... I would suspect your User-Agent string. ... I suspect it is not your browser which is telling you that but the ... Another site which you could use for comparing browser functionality is: ...
    (microsoft.public.windowsupdate)
  • Still fails - giving up - Thanks anyway for your careful help
    ... Subject: Re: The Windowsupdate site redirects and fails ... > which immediately redirects in turn to ... the application your browser is connecting to. ... User-Agent string that each request contains? ...
    (microsoft.public.windowsupdate)
  • Re: My web
    ... You might need a javascript enabled browser for my website to ... To be able to access all features, you must have a browser that can ... which also redirects to another page ... Good job s/es don't have ears. ...
    (alt.internet.search-engines)
  • Fwd: cdimage.debian.org presents different faces for "ftp" and "http" access
    ... redirects me to ... but pointing my browser at ... been built and the http server still needs to be synced. ...
    (Debian-User)
  • Re: Difference b/w Admin and User accounts when running IE
    ... "redirects" me to another site/url. ... Is it an IE or Windows security problem? ... > trusted web content zone to see if it makes a difference and also check ...
    (microsoft.public.win2000.security)