Re: SQL on one machine, IIS6 on another: authentication troubles

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 04/13/04


Date: Tue, 13 Apr 2004 15:50:49 +1000

Integrated Security does work from NT, and 9x. However Integrated Security
consists of two sub-methods: Keberos and NTLM v2. Only Kerberos can be
delegated when you have a Windows 2000 domain.

I would suspect that you do not have delegation properly enabled for the
Windows server in question. Either the user, or the computer is not marked
for delegation in Active Directory -or- the browser is not using Kerberos to
authenticate (it may be using NTLM instead).

Cheers
Ken

"Todd" <spidur1@excite.com> wrote in message
news:A6C85DC9-CA90-4259-B5C9-EF2F0D4B63A3@microsoft.com...
: Hey guys, integrated security works fine except for when you connect from
a server OS such as windows 2000. Then you get the 'NT AUTHORITY\ANONYMOUS
LOGON' error. This is a problem for us because we have a citrix server that
uses our intranet. Any ideas? I know integrated security dosen't work on
NT or 95/98, but it should work with a server OS acting as a client,
shouldn't it?



Relevant Pages

  • Re: UNC Virtual Directories; NTFS permission authentication not ac
    ... If you want Kerberos delegation to work, you need to have everything setup correctly end-to-end. ... The browser must authenticate using Kerberos, which means that both IE must attempt Kerberos *and* the relevant server SPNs must be created/set correctly. ... > Windows Authentication option the ...
    (microsoft.public.inetserver.iis.security)
  • Re: Delegation through Linked Server Stops working
    ... "Troubleshooting Kerberos delation" is nearly a 90 page doc. ... you do when/if you open a ticket. ... This post was about delegation working and then suddenly ... delegation on linked server fails in our network when we use ...
    (microsoft.public.sqlserver.security)
  • Re: Delegation: IIS Server setup in typical 3-tier scenario.
    ... doesn't already have an SPN and/or you need to change the existing SPN. ... Kerberos is being used - it just means that an API is used to determine what ... so I'm trying to set up delegation. ... Authenticated using NTLM not Kerberos on the Web Server. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Routing Userrights to another ASP.Net Webapplication
    ... In order to make this type of scenario work, you need to implement Kerberos ... Kerberos delegation can be a challenge to set up, ... Server and all servers are in the same domain. ... I want to handle a request from the ASP.Net Application to the SharePoint ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: EFS error: event id: 6203 on Windows Server 2003
    ... Trusted for delegation was not enabled, but that didn't solve my problem. ... encrypted on our old file server which is in the meantime switecd off. ... Also to encrypt files ... > are using NTLM authentication rather than Kerberos. ...
    (microsoft.public.win2000.security)