Re: always dual entries in IIS Log with first being HTTP 401.2 error

From: Ohaya (ohaya_at_cox.net.NO_SPAM)
Date: 11/15/03


Date: Sat, 15 Nov 2003 07:56:08 -0500

Bernard,

I'm seeing something similar, when I have SSL and client auth enabled, but
instead of a 401 and then a 200, I'm getting a 500 then a 200.

If I disable client authentication, I only get the 200.

Is this normal???

"Bernard" <qbernard@hotmail.com> wrote in message
news:uSE5eK3qDHA.1880@TK2MSFTNGP09.phx.gbl...
> When IE make the first attempt to connect, it
> will always access as anonymous first, if it fail,
> then it will try different auth mode, refer this kb
> INFO: How IIS Authenticates Browser Clients
> http://support.microsoft.com/?id=264921
>
> --
> Regards,
> Bernard Cheah
> http://support.microsoft.com/
> Please respond to newsgroups only ...
>
>
>
> "Michael Chen" <v-michen@microsoft.com> wrote in message
> news:00d001c3aae5$5d471c80$a501280a@phx.gbl...
> > We noticed that, in our web log, every single request has
> > 2 entries. The first one always logged in cs-username, sc-
> > status, sc-substatus, and sc-win32-status as -, 401, 2,
> > and 2148074254, respectively. The second one logged
> > user's windows account, 200, 0, 0 in the corresponding
> > fields, respectively. One major concern is that the
> > second one lagged first one by up to 50 seconds in some
> > cases, although in majority of cases the lag is not
> > discernable.
> >
> > The server runs Windows2003 server enterprise edition.
> > The site requires integrated windows authentication as
> > well as SSL connection. The anonymous access is disabled.
> >
> > Does anyone have similar experience or some insight on
> > why it's happening?
>
>



Relevant Pages

  • Re: a refresher
    ... pages available to whoever you want to by controlling the authentication ... methods and using ntfs permissions.If you are talking about web enrollment, ... public key unencrypted to start the SSL process. ... session keys agreed upon by the client computer to start the session. ...
    (microsoft.public.win2000.security)
  • Re: clients editing information w/o authentication--advice needed
    ... I completely concur that username/password authentication is the way to go. ... SSL, while the most secure, is not essential since there's no confidential ... I will "push back" with the client and tell them they'd be better off ...
    (comp.lang.php)
  • SSL on OWA questions
    ... I have installed OWA on IIS4 server with SSL enabled on ... We are using basic authentication ... to OWA by client are encrypted by the SSL session? ... both side then why we need to install client ...
    (microsoft.public.inetserver.iis.security)
  • SSL und client authentication
    ... Kann man mit outlook 6 / outlook express 6 per SSL mit client authentication ... Ich bin sehr dankbar fuer jede Hilfe bzw. ...
    (microsoft.public.de.outlook)
  • SSL und client authentication
    ... Kann man mit outlook 6 / outlook express 6 per SSL mit client authentication ... Ich bin sehr dankbar fuer jede Hilfe bzw. ...
    (microsoft.public.de.german.inetexplorer.ie6.outlookexpress)