Re: Integrated Authentication - one way cross forest trust

From: mpriess (mpriess_at_directalliance.com)
Date: 02/06/04


Date: Fri, 6 Feb 2004 07:39:32 -0700

Thanks for replying Doug, but I found this article a few days ago and none
of the solutions apply to our particular scenario.

"doug" <anonymous@discussions.microsoft.com> wrote in message
news:bdaf01c3ecbd$d9698090$a501280a@phx.gbl...
> Does this help?
>
> http://www.eventid.net/display.asp?eventid=537&source=
>
> doug
> >-----Original Message-----
> >Hello everyone...here is my issue:
> >
> >When attempting to access a website on IIS6 we receive a
> dialog box to enter
> >username and password. If we enter a domain\username
> and password of an
> >account that is in the same forest that the web server
> is in...we are
> >authenticated fine and the web page comes up.
> >
> >However, if, from the same machine we enter in an
> account (prefixed with the
> >correct domain name) from the trusted domain (an account
> that is not in the
> >same forest as the web server...but does have
> permissions on the web site
> >and is in the trusted domain) we are unable to get past
> the authentication
> >pop up dialog box.
> >
> >Some other important info:
> >There is a one way trust in place. All other
> authentication to the trusting
> >domain is fine. So, this would lead me to believe it is
> specific to IIS.
> >Another web server has been brought up and we are
> receiving the same auth
> >issues. Sharepoint is running on this IIS server but
> the proper permission
> >have been given to the user we are attempting to
> authenticate with so we do
> >not believe this has anything to do with the problem.
> Also, the firewall
> >between both subnets is being monitored and no traffic
> related to the
> >authentication or web requests is being dropped.
> >
> >The security event log on the web server shows the
> following: (the domain
> >name has been changed here)
> >
> >Event Type: Failure Audit
> >Event Source: Security
> >Event Category: Logon/Logoff
> >Event ID: 537
> >Date: 2/6/2004
> >Time: 6:17:13 AM
> >User: NT AUTHORITY\SYSTEM
> >Computer: DAC-NMS
> >Description:
> >Logon Failure:
> > Reason: An error occurred during logon
> > User Name: mpriess
> > Domain: dom123
> > Logon Type: 3
> > Logon Process: NtLmSsp
> > Authentication Package: NTLM
> > Workstation Name: DAC3812
> > Status code: 0xC0000413
> > Substatus code: 0x0
> > Caller User Name: -
> > Caller Domain: -
> > Caller Logon ID: -
> > Caller Process ID: -
> > Transited Services: -
> > Source Network Address: 172.31.7.55
> > Source Port: 4200
> >
> >For more information, see Help and Support Center at
> >http://go.microsoft.com/fwlink/events.asp.
> >
> >
> >.
> >



Relevant Pages

  • RE: prompted for username, password on iis5 running xp pro
    ... >Server will negociated an authentication method. ... >an valid username/password, the username/password box ... >the web server will send the content to the client. ... >the Web Server in Windows 2000 Server and Windows XP Pro ...
    (microsoft.public.inetserver.iis.security)
  • Re: Securing Windows Media Encoder streams/broadcasts
    ... >>The security comment was in response to the previous posters comment about ... >>protecting a URL and feeding the video on a web site, ... > authentication system yourself - as the previous poster stated, ... your web server on the encoder client machine modifies the ...
    (microsoft.public.windowsmedia.encoder)
  • RE: DMZ and AD Authentication
    ... authentication, and then permitting them users to access the AD for ... thru is the web server was compromised. ... I would recommend using the Cisco Security Agent on the web ... >Subject: DMZ and AD Authentication ...
    (Security-Basics)
  • RE: website inside or outside the domain?
    ... it is better not to have domain authentication traffic ... publicly accessible web server in a DMZ, with a DC also in the DMZ ... > webserver is ... network) its not the best model to use. ...
    (Focus-Microsoft)
  • Re: Integrated Windows Authentication not working
    ... >>> only web site and no one is behind a proxy server. ... proxy server between the various user's ISPs and your web server? ... And you're sure that the authentication settings for the virtual ... directory that maps to the physical directory where the .asp files are ...
    (microsoft.public.inetserver.iis.security)