<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>IIS7 - Security</title><link>http://forums.iis.net/1043.aspx</link><description>Discussions around the security of IIS 7 including compentization, hidden directories, or authentication\authorization</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Strange authentication problem</title><link>http://forums.iis.net/thread/1885753.aspx</link><pubDate>Mon, 24 Nov 2008 04:19:51 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885753</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885753.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885753</wfw:commentRss><description>&lt;p&gt;Check if you got the FREB tracing up.&lt;br /&gt;&lt;a href="http://learn.iis.net/page.aspx/266/troubleshooting-failed-requests-using-tracing-in-iis7/"&gt;http://learn.iis.net/page.aspx/266/troubleshooting-failed-requests-using-tracing-in-iis7/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Strange authentication problem</title><link>http://forums.iis.net/thread/1885644.aspx</link><pubDate>Fri, 21 Nov 2008 19:38:12 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885644</guid><dc:creator>tim.bishop</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885644.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885644</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="/Themes/iis/images/icon-quote.gif"&gt; &lt;strong&gt;anilr:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;&lt;p&gt;That is just the initial 401 challenge by IIS - are you not seeing any further requests with different sub-status codes/win32 codes?&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;&lt;p&gt;No, I don&amp;#39;t see any further requests other than repeats of that. Usually 3 times before the browser gives up and just displays the 401. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="/Themes/iis/images/icon-quote.gif"&gt; &lt;strong&gt;anilr:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;&lt;p&gt;Can you enable failed-request tracing and collect
some freb logs?&lt;/p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;p&gt;I&amp;#39;ve enabled that by going to the advanced settings on the site. But it&amp;#39;s not logging anything in the directory specified there. Is there anything else I need to do?&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Tim. &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Re: Strange authentication problem</title><link>http://forums.iis.net/thread/1885640.aspx</link><pubDate>Fri, 21 Nov 2008 19:31:29 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885640</guid><dc:creator>anilr</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885640.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885640</wfw:commentRss><description>&lt;p&gt;That is just the initial 401 challenge by IIS - are you not seeing any further requests with different sub-status codes/win32 codes?&amp;nbsp; Can you enable failed-request tracing and collect some freb logs?&lt;/p&gt;</description></item><item><title>Re: Strange authentication problem</title><link>http://forums.iis.net/thread/1885620.aspx</link><pubDate>Fri, 21 Nov 2008 17:51:39 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885620</guid><dc:creator>tim.bishop</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885620.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885620</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="/Themes/iis/images/icon-quote.gif"&gt; &lt;strong&gt;anilr:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;What are the sub-status/win32-status on the IIS logs?&lt;/p&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;sc-status is always 401&lt;/p&gt;
&lt;p&gt;sc-substatus is always 1&lt;/p&gt;
&lt;p&gt;sc-win32-status is always 2148074254&lt;/p&gt;
&lt;p&gt;Does that help? &lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Further to that, I created an Application (rather than a Virtual Directory) pointing at the same place and that&amp;#39;s working.&lt;/p&gt;

&lt;p&gt;Thanks for your help.&lt;/p&gt;

&lt;p&gt;Tim.&lt;/p&gt;</description></item><item><title>Re: Strange authentication problem</title><link>http://forums.iis.net/thread/1885616.aspx</link><pubDate>Fri, 21 Nov 2008 17:29:39 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885616</guid><dc:creator>anilr</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885616.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885616</wfw:commentRss><description>&lt;p&gt;What are the sub-status/win32-status on the IIS logs?&lt;/p&gt;</description></item><item><title>Strange authentication problem</title><link>http://forums.iis.net/thread/1885610.aspx</link><pubDate>Fri, 21 Nov 2008 16:19:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1885610</guid><dc:creator>tim.bishop</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1885610.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1043&amp;PostID=1885610</wfw:commentRss><description>&lt;p&gt;I&amp;#39;m running IIS 7 on Server 2008 Enterprise. The server is a DC running Exchange, although that may not be relevant.&lt;/p&gt;

&lt;p&gt;I create a directory called C:\test and put a single file called test.html in it.&lt;/p&gt;

&lt;p&gt;Then in the IIS Manager and create a virtual directory under the default site called test and point it at C:\test. Authentication is set to pass through. Then in the authentication section for the virtual directory I enable both Basic and Windows authentication.&lt;/p&gt;

&lt;p&gt;I then browse to http://localhost/test/test.html and get my page up. If I try it on another machine I get an auth prompt, enter my login, and then get the page.&lt;/p&gt;

&lt;p&gt;This works fine.&lt;/p&gt;

&lt;p&gt;Then a while later it stops working. I get repeatedly prompted for authentication and then finally get:&lt;/p&gt;

&lt;p&gt;401 - Unauthorized: Access is denied due to invalid credentials.
You do not have permission to view this directory or page using the credentials that you supplied.&lt;/p&gt;

&lt;p&gt;And it doesn&amp;#39;t work again after that.&lt;/p&gt;

&lt;p&gt;If I make a copy of C:\test to C:\test2, and then just edit the test virtual directory to point at C:\test2 it starts working again. For a while. Then it does the same behaviour.&lt;/p&gt;

&lt;p&gt;Something must be changing after a period of time. Any suggestions as to what that could be?&lt;/p&gt;

&lt;p&gt;Many thanks,&lt;/p&gt;

&lt;p&gt;Tim.&lt;/p&gt;</description></item></channel></rss>