How do I Implement single sign-on?



We are in the process of moving our company from an IBM Domino web
world to Microsoft. The first part of this is endeavor is to revamp
our corporate intranet site and run it under IIS, but we would like to
implement the new site using single-sign-on. The problem I am a
software/web developer not a network engineer.

Here is what I have so far:

1) Virtual PC running Win 2003 server acting as my Active Directory/
Domain controller and DNS server.

2) Virtual PC running Win 2003 server acting as my web serving running
IIS

3) Virtual PC running Win XP acting as a client.


a) I have made the virtual machines 2 & 3, members of my test domain
b) Everyone can ping each other by name or IP
c) I have created a test user account on my domain controller
d) I can login into the virtual network using the XP client and the
new test user account
e) I have created a virtual directory on the web server to point to a
test application that is configured to utilize "windows
authentication", and I have set the virtual directory properties to
use integrated authentication.

My problem occurs when I try to access my test application from a
browser on the XP client. I get prompted for a login id, but when I
enter my test user's login credentials, IIS will not accept them.

Have I missed a step in my configuration, or the setup of my domain?
Is there something on the IIS server that needs to be setup to
authenticate incoming users against the domain?

I'm at a loss and need help.

Thanks.
.



Relevant Pages

  • Re: WM5 can not sync to exchange
    ... I checked all the authentication settings and they are as you requested. ... After running the internet connection wizard I had to uncheck the Require ... On the SBS 2003 Server open the Server Management console. ... Open IIS Manager ...
    (microsoft.public.windows.server.sbs)
  • RE: WM5 can not sync to exchange
    ... code 85010014 during ActiveSync with SBS. ... On the SBS 2003 Server open the Server Management console. ... Please verify Authentication settings by the following steps. ... Open IIS Manager ...
    (microsoft.public.windows.server.sbs)
  • Re: Can login domain be set to a default?
    ... need for specifying a login domain. ... accounts of the IIS box (and the login process needs a way to ... cannot specify a default domain for Windows integrated authentication ... > The internal domain for the three servers is different than the web site ...
    (microsoft.public.windows.server.security)
  • Re: WM5 can not sync to exchange
    ... On the SBS 2003 Server open the Server Management console. ... Please verify Authentication settings by the following steps. ... Open IIS Manager ... Collect the IIS metabase on Exchange Server and send to me: ...
    (microsoft.public.windows.server.sbs)
  • Re: Directory Services, LDAP or similar
    ... In other projects, we managed the user authentication by creating tables that define all users and its allowed capacities, then the application queryies that data to verify if a user has access to some feature or not. ... The above ID and password are sent to the service at login time. ... They are using Novell eDirectory at the enterprise level; yes it's LDAP. ... We already do that for three different DB servers; ...
    (borland.public.delphi.non-technical)