Re: Issue: Virtual Directory to UNC
- From: Jay <Jay@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 18 Dec 2005 10:35:01 -0800
Hi David,
First of all, my thanks to you. I had done some research on the web before
turning on to TechNet. As I had specified in my post, I CANNOT use delegation
as I am not the domain administrator. Setting up of delegation rights has
been restricted only to the domain admins.
As my server is in the domain, and as the application requires proper
authentication for access, I was expecting a way to use the same to access
the UNC. Even if there needs to be a re-authentication, I guess that should
not be an issue at all, but I am not able to get it work.
I repeat, I CANNOT set the delegation property (Even constrained). The
reason behind my post is to check if it would work, as impersonation as the
request user works even without delegation for other applications like AD,
except getting this virtual directory to an UNC.
If there is no solution without delegation, then I will have to remove the
feature from the application and live with the fact that sometimes MS
products do suck :)
Rgds.
"David Wang [Msft]" wrote:
> Still looks like double-hop/delegation. The following URL should provide you
> all necessary options/configuration and details.
>
> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/webapp/iis/remstorg.mspx
>
> --
> //David
> IIS
> http://blogs.msdn.com/David.Wang
> This posting is provided "AS IS" with no warranties, and confers no rights.
> //
>
> "Jay" <Jay@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:7E585E7F-306E-4518-BD4C-766F161D5B70@xxxxxxxxxxxxxxxx
> > Hi,
> > I am configuring a virtual directory pointing to a UNC within the same
> > domain as the IIS server (Win 2003 server). The authentication setting is
> > set
> > to Network Credentials of Users. The rest all like Anonymous access, etc.
> > are
> > unchecked. ACLs are set up in the file server (UNC) thereby controlling
> > access on the list of people who would be accessing the file server
> > normally
> > without the IIS.
> >
> > Even though I have access to both the web server as well as the file
> > servers
> > seperately, I am not able to access the files using the virtual directory.
> > For ex: \\myserver1\fileshare is set to the virtual directory
> > http://myserver2/fileshare.
> >
> > Now when a file like say http://myserver2/fileshare/file1.ext is being
> > accessed, even though the credentials were supplied, it prompts for the
> > username and password as if the supplied credentials were incorrect.
> >
> > I thought it might be a double hop issue, but when I try to access the
> > path
> > from the server with http://myserver2/fileshare/file1.ext, even then, I
> > get
> > the same issue.
> >
> > I guess there should be no issue with IIS using the network credentials
> > directly. One catch is that as per the organisation's IT policy, web
> > servers
> > cannot be allowed delegation. Is there any way the above issue can be
> > resolved.
> >
> > Any help appreciated in advance.
> >
> > Rgds.
>
>
>
.
- Follow-Ups:
- Re: Issue: Virtual Directory to UNC
- From: David Wang [Msft]
- Re: Issue: Virtual Directory to UNC
- References:
- Re: Issue: Virtual Directory to UNC
- From: David Wang [Msft]
- Re: Issue: Virtual Directory to UNC
- Prev by Date: Re: Antivirus software for a webserver
- Next by Date: Re: Issue: Virtual Directory to UNC
- Previous by thread: Re: Issue: Virtual Directory to UNC
- Next by thread: Re: Issue: Virtual Directory to UNC
- Index(es):
Relevant Pages
|