Re: UPN in IIS5

From: handpix@sbcglobal.net
Date: 01/14/03


From: <handpix@sbcglobal.net>
Date: Tue, 14 Jan 2003 02:56:38 -0800

This was what i needed. Thank you sir!

MH

"BB" <Bernard_at_3exp.com> wrote in message
news:eBSVWJ4uCHA.2296@TK2MSFTNGP09...
> Are you using Basic authentication ?
> Not sure on multiple domains, but if it is
> under the same forest, there's implicit trust
> I believe. See if this kb help
> How to Enable UPN (or Single) Logon with Internet Information Services 5.0
> http://support.microsoft.com/?id=260269
>
> Rgds.
>
>
> <handpix@sbcglobal.net> wrote in message
> news:#1ElKd1uCHA.428@TK2MSFTNGP09...
> > I have IIS 5.0 running on Advanced Server. I a configuration that
requires
> > different internet domain users to be able to access this site. I have
set
> > up the folowing configuration.
> >
> > I added the upn's of the domains to the alternative UPN list under AD
> > Domains and Trusts. For the purpose of this example we will use the
> > following.
> >
> > domain1.com
> > domain2.com
> >
> > I then added users to each of the domains.
> >
> > user1 (with domain1.com selected as the upn)
> > user2 (with domain2.com selected as the upn)
> >
> > When i authenticate to IIS 5.0 i am unable to authenticate using the
full
> > UPN (user1@domain1.com) When i use this IIS gives a 403 Unauthorized
> error.
> > However using "user1" or "domain1\user1" authenticate fine. I have
> searched
> > the Q articles and found several referances to this type of problem and
> UPN
> > authentication errors on IIS pre sp1. I just re-ran SP3 on my system and
> am
> > still having this issue. Any assistance or ideas would be GREATLY
> > apprecaited. The end goal would be to be able to have the same user
alias
> > under different names so i can have different users one as
> admin@domain1.com
> > and another user admin@domain2.com. Thank you
> >
> > -mh
> >
> >
>



Relevant Pages

  • UPN in IIS5
    ... I have IIS 5.0 running on Advanced Server. ... I a configuration that requires ... I added the upn's of the domains to the alternative UPN list under AD ... When i authenticate to IIS 5.0 i am unable to authenticate using the full ...
    (microsoft.public.inetserver.iis.security)
  • Re: using UPN to auth
    ... Windows will then use the UPN instead of the samaccountname to ... BTW If your client support client canonicalisation you can authenticate as ... privileged information or confidential information or both. ...
    (comp.protocols.kerberos)
  • Kerberos.app AD UPN & SAM authentication issue
    ... Kerberos.app with an AD account with a different name for the UPN ... The SAM will authenticate but not the UPN? ...
    (comp.protocols.kerberos)
  • Re: Active Directory LDAP address book?
    ... which allows anonymous LDAP connections. ... Works fine as long as you authenticate. ... > Neil D. ... >> It's also referred to as your UPN. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Kerberos.app AD UPN & SAM authentication issue
    ... I think you have to differentiate between the different principal types. ... Also when using the UPN with the canonicalisation flag set AD returns ... The SAM will authenticate but not the UPN? ...
    (comp.protocols.kerberos)