IIS 6.0 Kerberos authentication
From: Eduard Timchenko (etimche_at_newsgroup.nospam)
Date: 07/05/05
- Previous message: s-p-a-m: "[IIS6] Cannot Access IIS Metabase Through IIS Admin Objects"
- Next in thread: Wei-Dong XU [MSFT]: "RE: IIS 6.0 Kerberos authentication"
- Reply: Wei-Dong XU [MSFT]: "RE: IIS 6.0 Kerberos authentication"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 5 Jul 2005 07:49:08 -0700
Hi,
I have AAA site (not default web site) in IIS 6 on Windows 2003 Server.
The AAA site uses Windows Integrated authentication.
I have a problem of accessing the AAA site using DNS or FQDN name from other
Windows 2003 Servers in the same domain - i have been prompted to enter user
and password and get error of wrong user or password (security log recieve
authentication failure messages).
I do succeed to access AAA site by using URL with IP address
Using AuthDiag tool i see that i have a problem with Kerberos Authentication
(SPN not set), but NTLM authentication succeeds (this is why URL with IP
works)
More than that - if i configure IIS to work in IIS 5 compatibility mode - i
do not have any problem to access the AAA site using DNS name or FQDN.
The Kerberos, NTLM settings and Security settings on all Windows 2003
servers seems to be correct. The IE settings of trusted sites & local sites
does not resolve a problem.
Could you help me to understand why the authentication fails and what to do
in order to use Worker Process Isolation mode?
Thanks
-- Eduard Timchenko Business Technology Solutions Group Verint Systems
- Previous message: s-p-a-m: "[IIS6] Cannot Access IIS Metabase Through IIS Admin Objects"
- Next in thread: Wei-Dong XU [MSFT]: "RE: IIS 6.0 Kerberos authentication"
- Reply: Wei-Dong XU [MSFT]: "RE: IIS 6.0 Kerberos authentication"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|