IIS6 - Virtual Directory to URL share, authentication problems.

From: Bob Eadie (robert_at_eadies.org.uk)
Date: 10/26/04


Date: Tue, 26 Oct 2004 19:05:56 +0100

I have IIS6 running on a Win2003 box within a mixed Win2000/Win2003 domain.

I have set up a Virtual Directory set up to a remote share, and selected
'pass users credentials' to authenticate, as some users have more access
than others to various folders within the share. Anonymous is also
selected, as anonymous users are allowed to access some folders on the share
( I have given 'everyone' read and browse permissions to those folders).
Integrated and Basic authentication are selected.

I have also given the server 'delegation' rights.

It works fine from WindowsXP machines within the domain.

It does not work for users logged on to our Windows2003 Terminal Servers,
but does work for an administrator logged on to the Terminal Servers.

It does not work for users accessing the IIS server as a published server
through our Windows2003/ISA Server2004 firewall.

The symptoms when it does not work are that the user is asked for
username/pw three times, and then the error 401.3 'access denied because of
the ACls in force'.

However, the IIS logs show that the correct domain\username is being used to
try to access the share.

The whole of the rest of a fairly complex Intranet web-site works fine, both
within the network, and from outside through the firewall.

Any help where I start to look next to resolve this? I have already studied
about a dozen MS knowledgebase articles without success. Many of them talk
about delegation facilities which are only available in a 'Native' Win2003
domain, and I can't make ours that as we have Win2000 Domain controllers (as
well as one Win2003 DC).

thanks,

Bob



Relevant Pages

  • Re: Big problem with permission
    ... also test if this work locally at the server, if yes, meaning the firewall ... is having 'additional' protection for ftp traffic... ... with LocalUser and individual user folders. ... User from the Internet will access the FTp server via a Watchguard ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)