<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'Kerberos'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=Kerberos&amp;orTags=0</link><description>Search results matching tag 'Kerberos'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>IIS Kerberos</title><link>http://forums.iis.net/p/1161483/1919538.aspx#1919538</link><pubDate>Mon, 05 Oct 2009 17:03:32 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1919538</guid><dc:creator>DSoare</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;Hi,&lt;br /&gt; &lt;br /&gt; I have Kerberos authentication turned on for one of our
internal web sites. I have fulfilled all of the prerequisites (SPN, IE
integrated authentication, and correct security zone) When I try to
authenticate to the site from a widows server 2003 machine the
authentication works fine. I have also found some XP workstations that
work fine. I can see in the wireshark dumps that Kerberos is being
used. I have tried to access the site from 3 other windows xp
workstations and it generates an internal server error.&lt;br /&gt; &lt;br /&gt; I used the monitoring tool in the Authentication &amp;amp; Access Control Diagnostics tool and I can see the error happening:&lt;br /&gt; &lt;br /&gt; Successful login:&lt;br /&gt; &lt;br /&gt; &amp;lt;AuthMonRow Number=&amp;quot;64&amp;quot; tid=&amp;quot;0xae4&amp;quot; Date=&amp;quot;09/29/2009 23:15:19.294&amp;quot;&lt;br /&gt; &amp;nbsp;Name=&amp;quot;AcceptSecurityContext&amp;quot; Result=&amp;quot;0x0&amp;quot; ContextAttr=&amp;quot;0x802&amp;quot;&lt;br /&gt; &amp;nbsp;Package=&amp;quot;Kerberos&amp;quot; UserName=&amp;quot;REMOVED&amp;quot;&lt;br /&gt; &amp;nbsp;ClientName=&amp;quot;REMOVED&amp;quot;&lt;br /&gt; &amp;nbsp;ServerName=&amp;quot;REMOVED&amp;quot;&lt;br /&gt; &amp;nbsp;time_taken=&amp;quot;63 ms&amp;quot;&lt;br /&gt; &amp;nbsp;/&amp;gt;&lt;br /&gt; &lt;br /&gt; Failed login:&lt;br /&gt; &lt;br /&gt; &amp;lt;AuthMonRow Number=&amp;quot;53&amp;quot; tid=&amp;quot;0x254&amp;quot; Date=&amp;quot;09/29/2009 23:15:15.872&amp;quot;&lt;br /&gt; &amp;nbsp;Name=&amp;quot;AcceptSecurityContext&amp;quot; Result=&amp;quot;0x80090300&amp;quot; ContextAttr=&amp;quot;0x0&amp;quot;&lt;br /&gt; &amp;nbsp;Package=&amp;quot;&amp;quot; UserName=&amp;quot;&amp;quot;&lt;br /&gt; &amp;nbsp;ClientName=&amp;quot;&amp;quot;&lt;br /&gt; &amp;nbsp;ServerName=&amp;quot;&amp;quot;&lt;br /&gt; &amp;nbsp;time_taken=&amp;quot;0 ms&amp;quot;&lt;br /&gt; &amp;nbsp;/&amp;gt;&lt;br /&gt; &lt;br /&gt;
I looked up the AcceptSecurityContext function and found that the error
result is &amp;quot;SEC_E_INSUFFICIENT_MEMORY&amp;nbsp; - The function failed. There is
not enough memory available to complete the requested action.&amp;quot;&lt;br /&gt; &lt;br /&gt; http://msdn.microsoft.com/en-us/library/aa374703%28VS.85%29.aspx&lt;br /&gt; &lt;br /&gt;
I know that can&amp;#39;t be the case, the same user was used on both attempts,
and the authentication header was smaller on the failed login.&lt;br /&gt; &lt;br /&gt; Any one have some insight\help?&lt;br /&gt; &lt;br /&gt; Thanks,&lt;br /&gt; &lt;br /&gt; Dwayne.&lt;/p&gt;</description></item><item><title>Re: Windows Authentication Failing in IIS with IE8</title><link>http://forums.iis.net/p/1161205/1918316.aspx#1918316</link><pubDate>Fri, 25 Sep 2009 15:40:11 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1918316</guid><dc:creator>WaterWolf12345</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Okay, I enabled kerberos logging as per this article: &lt;a href="http://support.microsoft.com/?kbid=262177" title="http://support.microsoft.com/?kbid=262177" target="_blank"&gt;http://support.microsoft.com/?kbid=262177&lt;/a&gt;&lt;/p&gt;&lt;p&gt;There&amp;#39;s now a couple of kerberos error messages in my event log, I don&amp;#39;t know if they were caused by IIS or not.&amp;nbsp; Error Code: 0xd KDC_ERR_BADOPTION and&amp;nbsp; Error Code: 0xd KDC_ERR_BADOPTION. I&amp;#39;ll have to see if I can figure out what they mean.&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Kerberos Authentication mystery with IE7</title><link>http://forums.iis.net/p/1160961/1917208.aspx#1917208</link><pubDate>Wed, 16 Sep 2009 16:57:17 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1917208</guid><dc:creator>filip.goris@flip.be</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;We have the most strange situation here when IE7 clients try to authenticate&amp;nbsp;on an IIS6-based intranet application. I hope somebody can help me explain.&lt;/p&gt;
&lt;p&gt;Our .asp application is running in domain &amp;quot;belgium.local&amp;quot;. Integrated Windows authentication works fine for users in that domain. Users&amp;nbsp;in domain &amp;quot;holland.local&amp;quot;&amp;nbsp;however&amp;nbsp;get a 401 error after a loooong timeout when&amp;nbsp;trying&amp;nbsp;to access the app. Their event logs show LsaSrv errors 40960 and 40961, which tells me it&amp;#39;s a Kerberos-thing. There&amp;#39;s a mutual trust between belgium.local and holland.local.&lt;/p&gt;
&lt;p&gt;We&amp;#39;ve been troubleshooting in all directions and&amp;nbsp;installed Firefox. Firefox showed us a login box, which told us it was failing over to Basic Authentication. That seemed right since it doesn&amp;#39;t use&amp;nbsp;Integrated Authentication&amp;nbsp;until you tell it to. So we told&amp;nbsp;it to use&amp;nbsp;Kerberos&amp;nbsp;by adding domain &amp;quot;belgium.local&amp;quot;&amp;nbsp;to &lt;em&gt;network.negotiate-auth.trusted-uris&lt;/em&gt; (which is about the same as enabling Integrated Windows authentication in IE7 and adding the site to my Local Intranet Zone. Cfr. &lt;a href="http://grolmsnet.de/kerbtut/firefox.html"&gt;http://grolmsnet.de/kerbtut/firefox.html&lt;/a&gt;&amp;nbsp;for example.)&lt;/p&gt;
&lt;p&gt;Now here&amp;#39;s the odd part.&amp;nbsp;After making this configuration change in Firefox, IE7 running on the same client computer will work too.&lt;br /&gt;&amp;quot;Ah, but that&amp;#39;s normal&amp;quot; I hear you say, &amp;quot;because the Kerberos ticket is still there and valid.&amp;quot;&lt;br /&gt;The strange thing is it will continue to work after I use Kerbtray to purge the tickets. My ticket for HTTP/app.belgium.local will show up again as soon as I visit the site with IE7. It is as if IE7 uses the Firefox configuration in some way to retrieve&amp;nbsp;a ticket.&lt;/p&gt;
&lt;p&gt;The really scary part is this: after I restore the Firefox configuration back to normal (e.g. delete all domains from the &lt;em&gt;network.negotiate-auth.delegation-uris &lt;/em&gt;setting), IE7 will continue to work!? It is as if somehow I showed it how to get at ticket when I configured Firefox, and it &amp;quot;remembers&amp;quot; this now.&lt;/p&gt;
&lt;p&gt;Can somebody tell me what is happening? I would like to get this to work without installing and removing Firefox on all my clients ;)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>IIS Session Timeout problem</title><link>http://forums.iis.net/p/1160915/1916985.aspx#1916985</link><pubDate>Tue, 15 Sep 2009 10:36:52 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1916985</guid><dc:creator>Usman Sadjid</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;I am having problems trying to work out if it is possible to share iis session timouts accross web applications in the following scenario: -&lt;/p&gt;&lt;p&gt;In my environment there are 2 IIS Web Servers on the same network domain.&lt;/p&gt;&lt;p&gt;One of the servers will host a .NET web application.&amp;nbsp; The other will host a COTS document management system (OpenText Livelink Enterprise Server) which is not a .NET web application.&amp;nbsp; Both web applications will be using windows authentication.&lt;br /&gt;&lt;/p&gt;&lt;p&gt; The COTS system will access the .NET web application such that when a User logs on to the COTS system, the .NET web application is accessed either via a web service or through a .NET aspx webpage.&amp;nbsp; The problem we have is that our client has a requirement in order to maintain iis timeouts accross both applications such that the same timeout period will effectively timeout a user from both the COTS system and the .NET web application at the same time.&amp;nbsp; By timeout, I mean require the user to re-authenticate.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;My first question is, is it possible to pass an authentication token through from the COTS web application to the .NET web application in this scenario.&amp;nbsp; Secondly and more importantly, is it possible to handle iis session timeouts as described above?&amp;nbsp; If so, could you please direct me to any articles that may be of use, as I can&amp;#39;t seem to find anything.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Any help would be greatly appreciated. &lt;/p&gt;&lt;p&gt;Thanks in advance. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Java-Applet authenticates with NTLM instead of Kerberos, Double-Hob-Issue</title><link>http://forums.iis.net/p/1160798/1916433.aspx#1916433</link><pubDate>Thu, 10 Sep 2009 14:09:57 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1916433</guid><dc:creator>Irgi</dc:creator><cs:applicationKey>iis7_-_security--1</cs:applicationKey><description>&lt;p&gt;I have a well running 3-tier web application in a Windows 2003 domain. The Internet-Explorer Clients call aspx-pages ont he webserver. The webserver then performs a DCOM call to a document management server using impersonation. It all works fine using only aspx pages. Checking the thread principal before doing the call to DCOM shows me the correct Windows-User on the client machine and the Authentication-Type &amp;quot;Kerberos&amp;quot;.&lt;/p&gt;&lt;p&gt;Here comes the problem:&lt;/p&gt;&lt;p&gt;There is a java-applet (which is a third party thing) in one of the webpages to allow the user to drag documents onto it and then it calls an aspx page to upload the document. &lt;/p&gt;&lt;p&gt;Checking the thread principal before doing the call to DCOM shows me
the correct Windows-User on the client machine but the
Authentication-Type &amp;quot;NTLM&amp;quot;. The thread now tries to call DCOM using the &amp;quot;Anonymous&amp;quot; user (I see this in the eventlog of the server that hosts the DCOM object) and throws an exception when i call Activator.CreateInstance(type). Looks like the classic &amp;quot;Double-Hop-Issue&amp;quot;.&lt;/p&gt;&lt;p&gt;Any ideas how to fix this or work around it?&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Help with backend failover cluster SPN delegation.</title><link>http://forums.iis.net/p/1160309/1914575.aspx#1914575</link><pubDate>Tue, 25 Aug 2009 16:30:05 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1914575</guid><dc:creator>Kapn.K</dc:creator><cs:applicationKey>web_farms--1</cs:applicationKey><description>&lt;p&gt;I have 2 network names. 1 for the cluster and one for the file server resource. When I configure the account, that runs app pools on my nlb, to delegate to the host and cif&amp;#39;s service(cluster attached to san), I use the file server name(b/c that&amp;#39;s what I specify in IIS file location), right? The person that built the cluster did so w/o creating the computer objects for the cluster name and file server name(we don&amp;#39;t have permissions to create the accounts but I can work with the people that do). Can I just create the file server name and spn&amp;#39;s for that name and give permission to the cluster service account? Or do I need to create the cluster name object as well?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;</description></item><item><title>One Domain App Pool account/server for Kerberos?</title><link>http://forums.iis.net/p/1160102/1913819.aspx#1913819</link><pubDate>Mon, 17 Aug 2009 18:57:44 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1913819</guid><dc:creator>Kapn.K</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;If I have multiple app pools on a server, and SPN&amp;#39;s created for each website(ie: setspn -a http\webapp1.example.com domain\account, and setspn -a http\webapp2.....), Will kerberos still work? I thought I read a while back the I can only have one account that all the app pools would run as or force NTLM.&amp;nbsp;Is this correct? I need kerberos due to remote webroots(on a SAN) and I wish to pass through credentials. Currently, I must request spn&amp;#39;s as I am not allowed to create them, myself. Can I only use one domain account per server?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;</description></item><item><title>How many SPN's do I need? NLB/MSCS</title><link>http://forums.iis.net/p/1159131/1909814.aspx#1909814</link><pubDate>Thu, 09 Jul 2009 21:04:15 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1909814</guid><dc:creator>Kapn.K</dc:creator><cs:applicationKey>web_farms--1</cs:applicationKey><description>&lt;p&gt;I have nlb groups and multiple sites(each site has own application pool).&lt;/p&gt;
&lt;p&gt;I would like to have one account that all the app pools run under.&lt;/p&gt;
&lt;p&gt;I couldn&amp;#39;t get kerberos working(necessary for remote file-share webroot) using the machine accounts but I was able to with a user account.&lt;/p&gt;
&lt;p&gt;Do I need to do this for each site(not machine)?&lt;/p&gt;
&lt;p&gt;setspn -A HTTP/website1.domain.com domain\service account&lt;/p&gt;
&lt;p&gt;setspn -A HTTP/website2.domain.com domain\service account&lt;/p&gt;
&lt;p&gt;Or does that cause the duplicate SPN? If so, do I need a separate service account for each site/app pool?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>NLB iis 6.0 trust for delegation to pass IWA credentials to MSCS file share.</title><link>http://forums.iis.net/p/1158194/1905968.aspx#1905968</link><pubDate>Fri, 05 Jun 2009 16:58:33 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1905968</guid><dc:creator>Kapn.K</dc:creator><cs:applicationKey>web_farms--1</cs:applicationKey><description>&lt;p&gt;I have 2 iis 6.0 boxes load balanced and the web files are located on a san that is shared by two clustered file servers. I&amp;#39;m trying to stay away from the &amp;quot;connect as&amp;quot; scenario so that I may leverage my ntfs permissions. In AD, I checked the &amp;quot;trust for delegation&amp;quot; check box for both of the iis machine accounts. All machines are in a 2003 functional level domain. If I uncheck integrated auth for the web site and check basic, I can enter my credentials and it lets me through. I&amp;#39;ve read the technet stuff but can&amp;#39;t seem to figure it out. Any help is greatly appreciated.&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;</description></item><item><title>Kerberos Delegation with Cross Forest Non-transitive Trust</title><link>http://forums.iis.net/p/1156925/1900764.aspx#1900764</link><pubDate>Thu, 16 Apr 2009 13:28:46 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1900764</guid><dc:creator>adweigert</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>I have two domains in separate forests with a two-way non-transitive trust, a resource domain and a user domain. The resource domain hosts an application and only allows certain users in the user domain to access it. There is an application tier that hosts a web service that the user credentials need to be passed to.

If I use a user in the resource domain, kerberos delegation works fine, however for users in the user domain I am seeing their authentication getting forced to NTLM instead of kerberos when access the web server in the resource domain.

I hope this makes sense and someone can tell me I cannot do this or that I can and might have a hint at what I might be missing. I am sure SPN and delegation settings are setup correctly, at least for users in the resource domain.

... Adam</description></item></channel></rss>