Re: Login Loop



On Mar 27, 1:46 pm, BigSam <Big...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
On our web server we have a virtual web site used to validate processes prior
to moving them into actual production. One of the steps we've taken is to
require a user ID & password. We are able to login fine, but after a page or
2 we are challenged again for the user ID & password. My developers insist
this is a configuration issue, but I tend to disagree. What causes the
sign-in challenge to re-appear?
We're running W2k3, SP2 with up-to-date Windows Updates.
The security settings are Integrated Windows Authentication & Basic
Authentication.


Re-appearing login prompts are never issues with the web server
because auto-login is a client-side optimization for authentication.

Thus, unless your developers added in custom authentication of their
own, your issue is either with the browser, the networking layer
between the browser and server, your configuration of the web server,
or the AD used by the web server.

The most direct way to prove where the problem lies is to obtain a
network-trace of the HTTP request/response that result in the
unexpected sign-in challenge. There are other ways, but they are all
indirect, and I do not recommend wasting time with indirect methods.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
.



Relevant Pages

  • Re: WebBrowser
    ... With a Windows Authentication or Permission on a folder ... With this type of security you may be able to access the ... If the login page is a Username / Password textbox with a Submit or Login ... send requests to a web server and get some type of response / data back. ...
    (microsoft.public.vb.controls)
  • Kerberos / Authentication to SQL2K
    ... Everything in the documentation indicates that setting the IIS settings to ... authentication until I switched on impersonation either. ... When set up on my web server however, I get the "Login failed for user ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Servlet authentication on Tomcat 5.5.7
    ... The Sun JDK provides a JAAS module for authentication against an NT machine ... With this JAAS login module ... against user database of the NT machine on which the web server runs. ...
    (comp.lang.java.programmer)
  • Re: Forms Authentication not functioning properly 100%
    ... > workstation (Windows 2000 Professional) in my office. ... when I move it to my Web Server which is running ... > Login page since I have not been authenticated. ... I have also tried a simple forms authentication ...
    (microsoft.public.dotnet.security)
  • [Full-Disclosure] Advisory: Dark Age of Camelot - Weak encryption of network traffic exposed persona
    ... Weak encryption in game client exposed customer billing and authentication ... encryption for billing information. ... The login binary has undergone several updates since then. ...
    (Full-Disclosure)