Re: IIS6 Basic Authentication and Kerberos



"pcarfan via WinServerKB.com" <u17416@uwe> ha scritto nel messaggio news:5a28f07b4d57c@xxxxxx
Greetings,

Hi

I have a web site on IIS6 using Basic Authentication. The account used to
access the site is a Domain Account on my Windows 2003 domain. The IIS server
is a member of the Windows 2003 Domain.


This IIS6 site is setup to run under its own Application Pool with a
configured identity that is a Domain User Account with the appropriate rights.



Everything is working great, however, I am trying to understand the underlying Kerberos.

1. Someone types in the wrong password for the domain account used to login
to the site.
2. On the web server a security event log is logged (expected).
3. On the first domain controller, an event log is logged about the failure
4. On the second domain controller an event log is logged about the failure.


Why does the web server attempt the authentication twice (once against each
domain controller)? Is this because it is failing twice (once at the IIS
Basic Auth and once at the underlying file perms)?

I suggest to read this document http://support.microsoft.com/?id=319723


--
Christian Paparelli
http://www.ithost.ch


.



Relevant Pages

  • Re: IIS 6 CreateObject premissions issue
    ... >> tier system so I am confident that running on Windows 2000 what I am ... >> What I am attempting is to add a Windows 2003 server box to function as ... However if it is set for anonymous access using the ... >> end boxes to specifically allow the Domain account I attempted to use as ...
    (microsoft.public.inetserver.iis.security)
  • Re: Domain admin cannot run program on SBS Domain Controller
    ... server. ... I get an error "Windows cannot access the specified device path ... logged on with my domain account, and my account is a member of the Domain ...
    (microsoft.public.windows.server.sbs)
  • RE: Virus is getting domain account listing
    ... and valid value in Windows 2000. ... For Windows Server 2003, I'd recommend inspecting the available Group Policy ... Virus is getting domain account listing ...
    (Focus-Microsoft)
  • Re: IIS NT authentication , can not access HDD on other NT server
    ... since AFAIK the IIS server using Windows integrated ... > authentication as if they were sitting at the console of the IIS computer. ... > an identical ID and password set up on the target server. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Local / Roaming Protocol
    ... Please visit the server experts in the server newsgroup: ... Get Windows XP Service Pack 2 with Advanced Security Technologies: ... | roaming profile and then for a local user profile. ... | my domain account. ...
    (microsoft.public.windowsxp.security_admin)

Loading