Previous Next

Thread: IIS 5.0 Win2k Advanced Server - HTTPS authentication failing

Last post 07-10-2008 10:46 PM by BearGFR. 2 replies.

Average Rating Rate It (5)

RSS

Page 1 of 1 (3 items)

Sort Posts:

  • 07-04-2008, 2:27 PM

    • BearGFR
    • Not Ranked
    • Joined on 07-04-2008, 2:15 PM
    • Posts 2
    • BearGFR

    IIS 5.0 Win2k Advanced Server - HTTPS authentication failing

    This seems weird to me.  I have IIS 5.0 /Win2k Advanced Server running and have a site that is protected via SSL (set to require a secure channel).  I've had this up and running for a couple of years or more, with no problems.  Then, about a week or so ago, I lost the ability to log into my secure site from the external internet.  I still get the login prompt, but when I enter the username/password the login fails.  The server's security event log clearly shows 681 events with error code 3221225578 which is invalid id/password.  The thing is though, I can log onto the domain controller or any machine in the domain with the very same credentials so I know the id/password are both correct.  It only fails when trying to access the secure web site.  This really did work for a couple of years, up until recently - honest.

    Any idea what I might be missing, or any suggestions on how to further diagnose the problem?

     Thanks,

    Bear

  • 07-10-2008, 7:56 PM In reply to

    • naziml
    • Top 500 Contributor
    • Joined on 03-10-2008, 6:25 PM
    • Posts 13
    • naziml

    Re: IIS 5.0 Win2k Advanced Server - HTTPS authentication failing

    Are you using Basic Auth with windows user credentials?

  • 07-10-2008, 10:46 PM In reply to

    • BearGFR
    • Not Ranked
    • Joined on 07-04-2008, 2:15 PM
    • Posts 2
    • BearGFR

    Re: IIS 5.0 Win2k Advanced Server - HTTPS authentication failing

    No, basic auth is disabled.  I'm only using Windows Intergrated Authorization.

     I was able to finally get it working again, although I'm not positive what did the trick.  I went through all the recommendations in http://support.microsoft.com/kb/271071/

    In the process of working through setting all the permissions, I found some orphanned SID's.  Not sure what they were or used to be, but I also got rid of the policy references to them.

    I also made sure that the LAN Manager Authentication Level policy was set to Send LM & NTLM - use NTLMv2 session security if negotiated

    After doing all that, it started working again.  I'm still not sure what happened to break it.

    Bear

Page 1 of 1 (3 items)
Page view counter