Handling HTTP 500 Account Locked

From: kevin (kevin5290@yahoo.com)
Date: 02/06/03


From: kevin5290@yahoo.com (kevin)
Date: 6 Feb 2003 11:51:14 -0800


When a user's account has been locked due to password violations and
subsequently the user logs into our web site using the correct
password, IIS returns an HTTP 500 error with a message of "The
referenced account is currently locked...".

The user never sees this information because IE "eats" the error
message and displays a generic "page cannot be displayed message".
This is due to the browser option "Show Friendly HTTP error messages"
being selected, which it seems to be by default. This is causing our
users alot of grief because they don't always realize that their
account is locked.

I have researched this issue thoroughly and cannot find much mention
of it on MSDN or elsewhere. Please confirm if there is no workaround
besides coding an ISAPI filter to catch the HTTP 500 error and change
it before being sent to the browser.

We're using Win2k, IIS 5.0, Active Directory with Digest
Authentication.

Thanks.



Relevant Pages

  • Re: Windows 2003 remote admin access
    ... access done in context of the authenticated browsing account (i.e. ... be limited to areas defined as vdirs in IIS and/or FTP. ... particular ports inbound so access on any other ports shouldn't be ... The user does have HTTP and FTP web authoring access but this ...
    (microsoft.public.security)
  • Re: Handling HTTP 500 Account Locked
    ... >referenced account is currently locked...". ... >This is due to the browser option "Show Friendly HTTP error messages" ... >it before being sent to the browser. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Host Company web on SBS 2003
    ... HTTPS and RWW requires that the user know an account and password, ... and the typical attack methods of HTTP don't work until the account ... In HTTP your server is processing anything they throw at it before ... Traffic must work its way through IIS to get authenticated. ...
    (microsoft.public.windows.server.sbs)
  • Re: Host Company web on SBS 2003
    ... HTTPS and RWW requires that the user know an account and password, ... In HTTP your server is processing anything they throw at it before ... Traffic must work its way through IIS to get authenticated. ... spam999free@xxxxxxxxxx (remove 999 for proper email address) ...
    (microsoft.public.windows.server.sbs)
  • RE: SOME Users cannot access OWA others do, error HTTP 500
    ... I understand that some account access OWA ... IIS 6.0 compression corruption causes access violations ... compressed copy of the affected files on the SBS server: ...
    (microsoft.public.windows.server.sbs)