IIS6 with IWA always using NTLM



Sorry for the cross-post - I posted this to inetserver.iis before I realized
there was a special security group.
-------

I've got a Windows Server 2003 box running IIS. I'm trying to use Kerberos
for authentication, so I can use delegation to access a remote server. For
some reason, the server seems to always be using NTLM to authenticate the
client - it never uses Kerberos. At least, that's what the Event Log shows
for the login request (which succeeds, it just isn't delegatable). I've
followed all of the documented steps for configuring a machine for
delegation. I've also Googled like crazy, and haven't found any resolution.

I've verified that there's a HOST SPN for the machine. I'm using the NetBIOS
name. I've used adsutil.vbs to explicity set the authentication mode to
Negotiate, NTLM. I've verified that the client is receiving Negotiate in the
HTTP header.

Meanwhile, there's another server that's sitting right next to it that
authenticates the same client with Kerberos just fine. These are both
freshly installed boxes (I've even reinstalled the one that isn't working).

Any idea how I can further diagnose the problem? It's driving me nuts.




.



Relevant Pages

  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: PROBLEM: ASP on IIS 5 secured via "Windows Integrated Authentication" accessing "
    ... I have two virtual directories on same server with Integrated ... If i use basic authentication, ... as .NET framework config file) as well as Delegation as specified by the ... > could do whatever you want in your ASP page on behalf of the Domain Admin. ...
    (microsoft.public.inetserver.iis.security)
  • Re: SSPI Kerberos for delegation
    ... We want the authentication to happen without providing credentials ... But SSPI while authenticating from the client to the server can do mutual ...
    (comp.protocols.kerberos)
  • Re: Aironet 1200/Radius Help Needed
    ... I just fired up a W2003 Advanced Server so that I can take ... >> IAS servers (do I need a separate certificate for the secondary IAS ... >> of authentication since it involves just installing the certificate on ... >between the AP and the client. ...
    (microsoft.public.internet.radius)
  • Re: Windows Authentication, Single sign on and Active Directory
    ... service proxy client fails to connect due to authentication failure and then ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... The server is always in the domain. ...
    (microsoft.public.dotnet.framework.aspnet.security)