Re: Windows Integrated Authentication on standalone server

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 06/16/05


Date: Thu, 16 Jun 2005 12:55:50 +1000


"Tom Kaminski [MVP]" <tomk (A@T) mvps (D.O.T) org> wrote in message
news:%23tUA0uacFHA.3204@TK2MSFTNGP12.phx.gbl...
: "Ken Schaefer" <kenREMOVE@THISadOpenStatic.com> wrote in message
: news:OgnKJoTcFHA.3040@TK2MSFTNGP14.phx.gbl...
: > "Tom Kaminski [MVP]" <tomk (A@T) mvps (D.O.T) org> wrote in message
: > news:%23G$vCnOcFHA.2124@TK2MSFTNGP14.phx.gbl...
: > : "Oyvind" <oyvind@nospam.no> wrote in message
: > : news:%23%23oENpLcFHA.3464@tk2msftngp13.phx.gbl...
: > : > Hi.
: > : >
: > : > I wish to use Windows Integrated Authentication in IIS to
authenticate
: > : > users logging on. The problem is that the web server is a standalone
: > : > server located in DMZ, and I wish to authenticate using domain
: > accounts.
: > : >
: > : > Am I right to assume that this is not possible, as long as the web
: > server
: > : > is not in a domain trusted by the domain users are authenticated
with,
: > or
: > : > member of that domain ?
: > : >
: > : > Will the only solution then be, to add the web server to a new
domain,
: > and
: > : > trust that domain (or add it to the already existing domain.) ?
: > :
: > : The whole point of Windows Integrated authentication is to use a
domain.
: >
: >
: > That's not true. IWA will work fine for accounts local to the webserver.
: > There is no requirement for a domain.
:
: OK - what would be the benefit?

IWA describes a method of conveying a users credentials from the client to
the server (basically a way of having the client tell the server who the
client is). As such, it competes with Basic and Digest authentication
mechanisms. So Basic Auth can be used for local -or- domain accounts, and
IWA can be used for local or domain accounts as well.

Where/how the organisation manages the username/password store that the
server has access to is a completely separate matter. The arguments
regarding Domains -vs- Workgroup (local accounts) are the same regardless of
whether you are using Basic, Digest or IWA (NTLM or Kerberos)
authentication. [1]

Cheers
Ken

[1] Well, there's a limitation in Windows that Digest can't be used with
local accounts because an MD5 hash of the user's password can not be
calculated for a local user (there is no facility for storing passwords with
reversible encryption, and no facility for storing a pre-calculated hash).
But that is not a limitation in either the Digest standard or IIS, but how
the Windows local SAM was developed.



Relevant Pages

  • Re: Win2K3 domain account connecting to Win2K VPN server in an NT4
    ... - since the server is not in the AD domain, you can't add it to the AD ... NT4 accounts can still authenticate, ... I verified that my test accounts could connect to the VPN before migrating ... > The authentication server did not respond to authentication requests in a ... ...
    (microsoft.public.win2000.ras_routing)
  • Re: Digest Authentication - IIS6
    ... I am fighting with a web site to setting up to use Digest ... If I setup the website with Basic authentication works fine (for the ... It happen on a Windows 2003 Server R2, IIS6, Application Pool was ... Your english is better then most people who were born in the US:) ...
    (microsoft.public.inetserver.iis.security)
  • Re: Removing SPA from POP3 service of Windows 2003 Server
    ... If you wish to change the authentication type from "Local Accounts" to ... right-click on the server and bring up the properties. ... I think what you need to do is configure your Outlook accounts, ...
    (microsoft.public.windows.server.security)
  • Re: SBS Standard 2003 Email Out Problem
    ... For authentication, are you using the main account and password you ... The settings for smarthost are all in place; but the server will not ... Cannot get emails out through external email host ... sent mail to external email accounts returns with: ...
    (microsoft.public.windows.server.sbs)
  • Re: outlook prompts for credentials
    ... accounts reside. ... Domain B account which doesn't have the same SID as the user in Domain ... chose domain-wide authentication or forest-wide authentication which ... server without being asked for credentials... ...
    (microsoft.public.exchange.clients)