Re: IIS and Kerberos problem

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 03/22/05


Date: Tue, 22 Mar 2005 23:42:18 +1000

a) Check what authentication types are being sent by the server to the
client. You need WWW-Authenticate: Negotiate for Kerberos to work. Use
WFetch or telnet to verify this. WFetch is part of the IIS Resource Kit
Tools which you can download:
http://www.microsoft.com/downloads/details.aspx?FamilyID=56fc92ee-a71a-4c73-b628-ade629c89499&DisplayLang=en

b) Ensure that "Enable Integrated Windows Authentication (requires a
restart)" is enabled on the client (Tools -> Internet Options -> Advanced),
so that the IE client uses Kerberos

c) IE will not use Kerberos is the site is in the "Internet" security zone.
So, if the site is accessed by IP address, or FQDN then you will need to add
it to the "Intranet" security zone on your IE clients (either manually,
using script, or using Group Policy)

Cheers
Ken

"TechMasters" <kiosk@comcast.net> wrote in message
news:1v30411gfqaj029tcns65mklvosfv6js6s@4ax.com...
:
:
: I just found out via the security log on the web servers (win2003)
: that my win2k clients are authenticating to the web servers with NTLM
: vs. Kerberos. Web servers and clients are all part of a win2k based
: native domain and the web site is set for Windows Authentication
: only....however the security log on the web server clearly shows NTLM
: as authentication instead of kerberos....any ideas??



Relevant Pages

  • Problems unwrapping SPNEGO token for Single Signon (SSO) in WebLogic Server 8.1.
    ... but cannot get WebLogic to unwrap the SPNEGO token so it authenticates using Kerberos. ... We've tried adding the AllowTGTSessionKey registry key on client and server, but that didn't change it either. ... Enable Integrated Windows Authentication ...
    (comp.protocols.kerberos)
  • Re: request for comments : slush
    ... You then connect back out via SSH client, ... > servers with SSH encryption, you may need to revisit your hardware ... have strong authentication without crypto overhead or multi-step protocols. ... RSH comes close, but it has a couple of drawbacks related to ...
    (comp.security.ssh)
  • Re: Using Kerberos in Windows 2000 Clustering
    ... Windows 2003 servers drop down to using LAN Manger authentication for ... the information about the cluster’s use of Kerberos and LM isn’t ... client can use this authentication method. ... Does the cluster software also drop down to using LM or will ...
    (microsoft.public.windows.server.clustering)
  • Re: NTP authentication using kerberos
    ... Is it possible to use kerberos in authentication with an ntp server? ... In the handbook regarding kerberos (and nearly every other ... And so far I have only found simple key authentication similar to dhcp ... It's good for NTP servers, ...
    (freebsd-questions)
  • Re: NTP authentication using kerberos
    ... Is it possible to use kerberos in authentication with an ntp server? ... In the handbook regarding kerberos (and nearly every other ... And so far I have only found simple key authentication similar to dhcp ... if you have your own heirarchy of Stratum 1 and perhaps Stratum 2 servers and accurate timing really is critical for you. ...
    (freebsd-questions)