Re: Weird Behaviour Accessing MS CA Web Site



"Hilding" <Hilding.Peterson@xxxxxxxxx> wrote in message
news:7803079f-32f4-4396-8664-aaac4193edb7@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I'm accessing the Certsrv pages from a Windows XP client, the CA is
Win2K3 Enterprise. If I access it using FQDN or NETBIOS I get a basic
challenge - and even with the correct credentials I can't logon (after
clicking OK in the basic prompt it just re-appears again). If I
access it using IP-Address, I get a basic challenge and I can access
the site.

Strange thing is, I've tried adding FQDN and NETBIOS into intranet
zone, but it doesn't change the behaviour; using the IP address relies
on the Internet zone.

On the CA itself, I can access certsrv using NETBIOS or IP address,
entering FQDN gives me a basic prompt and the same problem described
above.

I originally had the problems on IE6, so I upgraded to IE7 but the
problems are exactly the same.

Anyone had any similar problems with certsrv? Any ideas?

When you use IP you are forcing that Kerberos not be used.
Perhaps NTLM authentication is successful but when accessing other
than by IP Kerberos is result from the auth negotiation but then the login
via Kerberos is failing. Have you examined the security event log if it
is configured to record login failures?


.



Relevant Pages

  • Re: Name resolution vs. multiple NICs
    ... how exactly do you obtain it from a NetBIOS name? ... All you can physically get is what is FQDN as it appears to ... > with their ISP's domain suffix attached to it, ... > any domain suffix. ...
    (microsoft.public.win32.programmer.networks)
  • Re: Cannot Use LAN IP Addresses
    ... I haven't seen problems with Netbios names,...they usually work. ... recognized as a FQDN as opposed to a Netbois name is by the fact that the ... Phillip Windell www.wandtv.com "A.Klimkin" wrote in message ... >> after they are resolved to an IP#,...so they always are proccessed by the>> proxying service. ...
    (microsoft.public.isa.clients)
  • Re: Map the FQDN to a content source issue
    ... This error is usually because of the proxy settings. ... > content sources to the netbios name. ... > pointing the FQDN to the internal IP returns an error in the gatherer log ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Cannot Use LAN IP Addresses
    ... I haven't seen problems with Netbios names,...they usually work. ... recognized as a FQDN as opposed to a Netbois name is by the fact that the ... Phillip Windell www.wandtv.com "A.Klimkin" wrote in message ... >> after they are resolved to an IP#,...so they always are proccessed by the>> proxying service. ...
    (microsoft.public.isaserver)
  • Re: NT4/2K3 DNS Domain Name - Fallback Issues
    ... I think the name is not changed, just the FQDN are added. ... Are you meaning the NetBIOS Name ... >> Microsoft MVP - Directory Services ... >>> If the upgrade is successful in production this would be fine, ...
    (microsoft.public.windows.server.active_directory)