Re: Overcomplicating an OS: NTLM, Kerberos, Win2003/2000 incompatibility.

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 10/08/04

  • Next message: Roger Abell [MVP]: "Re: "LocalSystem" account privilege"
    Date: Fri, 8 Oct 2004 14:11:32 +1000
    
    

    This doesn't make sense. You seem to have the following setup:

    Client -> Windows 2003 (with SPS) -> Web Service on Windows 2000

    In this case, you do not need to mark the Windows 2000 computer as "trusted
    for delegation". You need to mark the WIndows 2003 machine as "trusted for
    delegation"

    Why would you have 50,000 Windows 2003 machines that need to be trusted for
    delegation?

    In any case, what does this have to do with your original post? You
    complained about incompatible authentication. You said:
    "Someone at Microsoft decided that IIS on 2003 will be using incompatible
    authentication by default with 2000's IIS, and that's it, SharePoint on 2003
    is not able to access the web services on 2000."

    What is incompatible? Please be precise, please don't just post vague
    comments about things. That way we can help you with your problem. On the
    other hand, if you just want to rant and complain, please make it clear that
    you are doing so, so that we don't waste time looking at your problem.

    Thanks

    Cheers
    Ken

    "G. Tarazi" <Tarazi (at) LiveTechnologies.ca> wrote in message
    news:OYkTBFHrEHA.3744@TK2MSFTNGP10.phx.gbl...
    > So simple
    >
    >
    >
    > Install Active Directory (PC1)
    >
    > Install Windows 2003 Server / SharePoint PC2
    >
    > Install Windows 2000 Pro PC3 (for the software developers) / VS.NET C#
    >
    > Add all to the domain.
    >
    > Create a SPS site on Win2003
    >
    > Create a Web service in Win2000
    >
    > Disable the anonymous connection and keep the windows authentication on
    > both
    > IIS
    >
    > Call the web service (that is on W2000) in the new SPS site. W2003
    >
    >
    >
    > And then you will realize what I am talking about, the W2003 is using
    > Kerberos the W2000 not. And making them compatible according to
    > support.microsoft.com means making W2000 trusted for delegation, it can
    > happen in an environment where there is 5 Pc's, but when you have 50,000 I
    > don't think so.
    >
    >
    >
    >
    > "Ken Schaefer" <kenREMOVE@THISadOpenStatic.com> wrote in message
    > news:%23MQ3evBrEHA.2904@TK2MSFTNGP15.phx.gbl...
    >> ?!?
    >>
    >> What authentication is "incompatible"?
    >>
    >> Do you really know what you're talking about? Or are you just ranting
    >> because you ran into something you didn't quite understand?
    >>
    >> Cheers
    >> Ken
    >>
    >>
    >> --
    >> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    >> "G. Tarazi" <Tarazi (at) LiveTechnologies.ca> wrote in message
    >> news:uBPUdU8qEHA.556@tk2msftngp13.phx.gbl...
    >> I am just not getting it
    >>
    >> There is a web server with Windows 2003 and a SharePoint server on it,
    >> and
    >> there is a 2000 server with .net 1.1 and web services on it, and both are
    > on
    >> the active directory and there are thousands of computers there.
    >>
    >> Someone at Microsoft decided that IIS on 2003 will be using incompatible
    >> authentication by default with 2000's IIS, and that's it, SharePoint on
    > 2003
    >> is not able to access the web services on 2000.
    >>
    >> And that causes tons of treble and hundreds of lost hours of
    >> productivity.
    >>
    >> Think about it next time, before someone says "Do more with less".
    >>
    >>
    >
    >


  • Next message: Roger Abell [MVP]: "Re: "LocalSystem" account privilege"

    Relevant Pages

    • Re: Windows Authentication method on IIS6
      ... The microsoft.public.windows.server.* groups deal with Windows 2003 ... The microsoft.public.inetserver.* groups deal with IIS ... > the authentication button, ... You can configure either one or multiple realm names on a server running IIS ...
      (microsoft.public.win2000.security)
    • Re: How to access Windows IIS User Info with Perl
      ... but the IIS server is configured for Windows ... allowed for Basic Authentication, Windows Authentication (or whatever ... Do you know if they are part of a standard ...
      (comp.lang.perl.misc)
    • Windows Authentication with IIS on separate machines
      ... Yes, setting Basic Authentication in IIS works, but the ... >in SQL server but doesn't work if user account was ... >imported from a Windows account. ...
      (microsoft.public.sqlserver.security)
    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... IIS Resource Guide). ... I next looked a little into Windows 2003. ... IMHO, the label on the option, "Enable Integrated Windows Authentication", ... the documentation leads one to ...
      (microsoft.public.windows.server.security)
    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... IIS Resource Guide). ... I next looked a little into Windows 2003. ... IMHO, the label on the option, "Enable Integrated Windows Authentication", ... the documentation leads one to ...
      (microsoft.public.inetserver.iis.security)