Re: Event ID 537 Digest Authentication

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 08/23/05


Date: Tue, 23 Aug 2005 14:56:25 +1000

Ouch:

0xC000006D =
STATUS_LOGON_FAILURE
The attempted logon is invalid. This is either due to a bad
username or authentication information.

0xC00000FE =
 STATUS_NO_SUCH_PACKAGE
 A specified authentication package is unknown.

Not really sure what the problem is. From your configuration information,
you didn't mention the following:
- are you running the worker process as LocalSystem?
- you have UseDigestSSP set to 0 (or not set at all) in the metabase for the
appropriate node?

Also, have you tried using AuthDiag (from the MS website) to see if there is
any other config that might need to be set? IIRC AuthDiag does some basic
config checking

Cheers
Ken

-- 
IIS Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com
"Isaac" <Isaac@discussions.microsoft.com> wrote in message 
news:68B079B8-51AC-438A-88E8-6549FA5637BB@microsoft.com...
: Yes to your second question.
:
: Event details:
:
: Logon Failure:
:  Reason: An error occurred during logon
:  User Name: isaacftp
:  Domain: strategicinc.com
:  Logon Type: 3
:  Logon Process: WDIGEST
:  Authentication Package: WDigest
:  Workstation Name: -
:  Status code: 0xC000006D
:  Substatus code: 0xC00000FE
:  Caller User Name: -
:  Caller Domain: -
:  Caller Logon ID: -
:  Caller Process ID: -
:  Transited Services: -
:  Source Network Address: 10.16.16.56
:  Source Port: 1640
:
:
:
:
:
: "Ken Schaefer" wrote:
:
: > Hi,
: >
: > I'm not familiar enough with Digest Authentication to know exactly 
what's
: > going wrong here, however:
: >
: > a) Can you post all the details of the 537 event please?
: >
: > b) After enabling "store passwords using reversible encryption" for the 
user
: > in question, did you reset their password? (so that the reversible 
version
: > is now stored?)
: >
: > Cheers
: > Ken
: >
: > -- 
: > IIS Blog: www.adopenstatic.com/cs/blogs/ken/
: > Web: www.adopenstatic.com
: >
: >
: > "Isaac" <Isaac@discussions.microsoft.com> wrote in message
: > news:F908C539-FA99-4B21-8360-92D4F3EA3246@microsoft.com...
: > :I have been fighting this for a few days now, so any help would be
: > : appreciated!!!!
: > :
: > : I am using a Windows 2003 SP1 server to setup a new website that will
: > : require authentication.  I have the only authentication for that web 
site
: > set
: > : to be digest authentication.  This machine is not a domain controller, 
and
: > my
: > : domain is Windows 2000.  I do have the following configured:
: > :
: > : Reversable encryption for user accounts
: > : Subauthentication installed on IIS server
: > : I have disabled the loopback check (even though I am doing an
: > : http://computername/folder)
: > : Realm is configured to my domain
: > :
: > : Everytime I try to athentication, my security log shows an event id 
537
: > for
: > : the WDIGEST logon process.  Browser (IE 6 SP1 latest and greatest 
patches)
: > : gets a 401.1 error as well.
: > :
: > : HELP!!!!
: >
: >
: > 


Relevant Pages

  • Re: Exchange, Event 537, and Access Denied, Oh my
    ... an error occurred during logon ... caller user name: - ... fails (which is what started me investigating this server in the first ... the authentication between the pda and iis occurs fine, ...
    (microsoft.public.windows.server.sbs)
  • Exchange, Event 537, and Access Denied, Oh my
    ... an error occurred during logon ... caller user name: - ... fails (which is what started me investigating this server in the first ... the authentication between the pda and iis occurs fine, ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange, Event 537, and Access Denied, Oh my
    ... There are a number of kb articles linked to the error there, allthough I don't see any exact matches other than the error code, indicating the that means "STATUS_LOGON_FAILURE", the attempted logon is invalid. ... (bad username or authentication) ... caller user name: - ... fails (which is what started me investigating this server in the first ...
    (microsoft.public.windows.server.sbs)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... as the case may be) which will delay authentication until ... I also have an Intel network adapter and WAP that does not have this> problem and even works well with 802.1X EAP-TLS for domain logon. ... In> most cases [ipsec a possible exception] kerberos authentication is not> needed to access domain resources as long as the client and server use a> common authentication method for lm/ntlm/ntlmv2. ... The main issue is to> NEVER include an ISP dns server in the preferred server list in the tcp/ip> properties or DHCP scope of any domain computer or any computer you want to> join to the domain in which case your computers may be trying to locate the> domain _srv records on the ISP dns server and fail. ...
    (microsoft.public.windows.server.security)