Re: Cannot use usernameForCertificateSecurity with IIS application pool custom account

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Steven,

Thanks for response. Regarding your questions:

My client needs to provide windows credentials to call the web service.
Because the client is supposed to connect over internet I cannot use windows
authentication. So IIS has windows authentication off and anymous access on.
As I have already stated, if I use only usernameOverTransport it works fine.
But when I switch to usernameForCertificate it fails - so this suggests that
the problem has to do something with the certificate.

I have set access to the certificate private key for the custom service
account and also I have used "aspnet_regiis -ga".

As I said in previous post it works fine if there is an active remote
desktop session logged into the same account in the time of using the web
service.

I am getting quite desperate as the code should go to production soon and I
still did not sort it out.

Martin


"Steven Cheng[MSFT]" <stcheng@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:4v$%238mNJHHA.2488@xxxxxxxxxxxxxxxxxxxxxxxxx
Hi Martin,

Just want to know whether you've turned on integreted windows
authentication on your webservice server machine and does your webservice
client also need to provide windows credential when calling the
webservice?
Based on my research, there are some issue (have similar symptom with you)
which is caused by kerberos authentication fails when server service is
using a custom account. So you've already use "anomymous access" for your
webservcie virtual dir in IIS, that should not be the problem.

Also, if you're using ASP.NET 2.0, you can use the "aspnet_regiis -ga"
command to grant the sufficient permission to a custom account that will
be
used to run ASP.NET application

http://msdn2.microsoft.com/en-us/library/k6h9cz8h(vs.71).aspx

If you have any other finding, please also feel free to post here.

Sincerely,

Steven Cheng

Microsoft MSDN Online Support Lead



==================================================

Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications.



Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.

==================================================



This posting is provided "AS IS" with no warranties, and confers no
rights.


.



Relevant Pages

  • RE: How to start/stop windows service on a remote machine?
    ... impersonate the client user(authenticated via integrated windows ... authentication in IIS) and access some remote protected resource(windows ... the problem you meet is a typical windows ... want to continue access other remote machine, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SP1 und Netzwerkauthentifizierung 802.1x
    ... Es gab mal ein Problem wenn das Client Certificat ... 953650 You cannot connect to an 802.1X wired network after you upgrade to Windows XP Service Pack 3 ... 838502 802.1x client authentication fails when you connect to a Windows Server ... IAS Best Practices: ...
    (microsoft.public.de.windows.vista.installation)
  • Re: Win98 and SBS2003
    ... Please also note that although you can use a Windows 98 clients in the ... 323466 Availability of the Directory Services Client Update for Windows 95 ... Microsoft Small Business Server Support ... features of Windows 2000 Professional that are related to Active Directory. ...
    (microsoft.public.windows.server.sbs)
  • RE: Error while installing "Windows Installer update "
    ... Wait for the policy to apply to the client machine (or force it to apply ... On a Windows 2000 client: ... Microsoft Online Partner Support ... Microsoft technology partners in the United States and Canada. ...
    (microsoft.public.windowsxp.general)
  • RE: 802.1x, Computers, Wired Security
    ... client to use EAP-TLS. ... Authentication-Provider = Windows ... Wired 802.1X Authentication failed. ... Network Adapter: Broadcom NetXtreme Gigabit Ethernet - Packet Scheduler ...
    (microsoft.public.windows.server.active_directory)