Re: "the function requested is not supported" on IIS6 with Win2K client

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 05/07/05


Date: Sat, 7 May 2005 23:44:49 +1000

Hi

Those settings do not affect HTTP based authentication (for example, LANMAN
is never used when authenticating between browser and IIS). They are for
things like SMB, NetBIOS etc.

You say you are getting a 500 error (Internal Server Error). In your copy of
Internet Explorer, please goto Tools -> Internet Options -> Advanced, and
uncheck "Show Friendly HTTP Errors", and reload the page. Post the full
error message you see now.

Cheer
sKen

-- 
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com
"news.microsoft.com" <ali_webitems@hotmail.com> wrote in message 
news:%231BgbRmUFHA.3584@TK2MSFTNGP14.phx.gbl...
: Hi all,
:
: I've just deployed a new IIS6 web server.  All of my XP-using clients are
: fine, but the Windows 2000 clients get a 500 error as soon as they try to
: connect & authenticate which turns out to be "the function requested is 
not
: supported"
:
: I found http://www.msusenet.com/archive/index.php/t-635508.html which got 
me
: 99% of the way there.  If I change the security policy on the client, they
: can get in.  However, we can't insist that everyone using our website 
change
: their security, so we need to change the policy on the server instead, and
: it's not working.
:
: The server was originally set to:
: Windows Settings / Security Settings / Local Policies / Security Options
: - Network security: LAN Manager authentication level
: - originally set to "Send NTLMv2 response only\refuse LM"
: - Network security: Minimum session security for NTLM SSP based (including
: secure RPC) clients
: - originally all four options checked
:
: The client was originally set to:
: - LAN Manager authentication level
: - originally set to "Send  LM & NTLM responses"
:
: If I change the client to "Send LM & NTLM - use NTLMv2 session security if
: negotiated" it works.  However, as I stated above, I don't want to change
: the client, I want to change the server.
:
: I've tried every combination I can think of on the server.  I've set it to
: "Send LM & NTLM - use NTLMv2 session security if negotiated" and to "Send
: LM & NTLM responses" and turned off all four checkboxes so it says "no
: minimum security" but it doesn't help.
:
: I've tried restarting the web site service, but have not rebooted.  On the
: client the change took effect immediately so I imagine it should on the
: server as well.
:
: Can anyone suggest what I'm missing?  I've searched TechNet and not found
: anything helpful.  From what I have found, the changes I made *should* 
have
: worked.
:
: Thank you very much,
:
: Beverley
:
: 


Relevant Pages

  • [Full-disclosure] [GOATSE SECURITY] Clench: Goatses way to say "screw you" to certificate author
    ... Application layer authentication-inherent validation of public key ... Goatse Security’s new simple password-based authentication mechanism ... getting hundreds of thousands or millions of users to install a client ... client hashes locally and then sends the hash to the server. ...
    (Full-Disclosure)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: SSPI Kerberos for delegation
    ... We want the authentication to happen without providing credentials ... But SSPI while authenticating from the client to the server can do mutual ...
    (comp.protocols.kerberos)
  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: Aironet 1200/Radius Help Needed
    ... I just fired up a W2003 Advanced Server so that I can take ... >> IAS servers (do I need a separate certificate for the secondary IAS ... >> of authentication since it involves just installing the certificate on ... >between the AP and the client. ...
    (microsoft.public.internet.radius)