IWA with multiple AD
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > IWA with multiple AD




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    IWA with multiple AD  
Tao Tao


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
04-21-05 10:55 PM

Hi, have a site on IIS 6.0 configured using IWA only, becaues that site will
grab user's logon information to keep track it.

people in same AD with IIS server logon fine with no issues. people in other
AD (same domain tree, sibling domains) got 401 error. while those users in
sibling domain can access that IIS box through netbios, etc, just fine.
(because there is trust between those domains).

any thought on how to get it fixed? any idea are greatly appreciated.

thanks.

Tao







[ Post a follow-up to this message ]



    Re: IWA with multiple AD  
Ken Schaefer


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
04-22-05 07:53 AM

Are the user's supplying their user-principal-name, or Domain\User as their
username? IIS 6.0 does not check all trusted domains by default.

Cheers
Ken

--
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com


"Tao Tao" <Tao Tao@discussions.microsoft.com> wrote in message
news:7AE1B25E-47B8-444E-A1A7-8CC7F8F96373@microsoft.com...
: Hi, have a site on IIS 6.0 configured using IWA only, becaues that site
will
: grab user's logon information to keep track it.
:
: people in same AD with IIS server logon fine with no issues. people in
other
: AD (same domain tree, sibling domains) got 401 error. while those users in
: sibling domain can access that IIS box through netbios, etc, just fine.
: (because there is trust between those domains).
:
: any thought on how to get it fixed? any idea are greatly appreciated.
:
: thanks.
:
: Tao
:
:







[ Post a follow-up to this message ]



    Re: IWA with multiple AD  
Tao Tao


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
04-22-05 11:00 PM

thanks, Ken.

the site is added in IE as trusted site, so IE automatically grab the
current AD login and submit them. users are not getting prompted for
credentials.

How can I configure IIS to check against other AD?

thanks a lot.

Tao

"Ken Schaefer" wrote:

> Are the user's supplying their user-principal-name, or Domain\User as thei
r
> username? IIS 6.0 does not check all trusted domains by default.
>
> Cheers
> Ken
>
> --
> Blog: www.adopenstatic.com/cs/blogs/ken/
> Web: www.adopenstatic.com
>
>
> "Tao Tao" <Tao Tao@discussions.microsoft.com> wrote in message
> news:7AE1B25E-47B8-444E-A1A7-8CC7F8F96373@microsoft.com...
> : Hi, have a site on IIS 6.0 configured using IWA only, becaues that site
> will
> : grab user's logon information to keep track it.
> :
> : people in same AD with IIS server logon fine with no issues. people in
> other
> : AD (same domain tree, sibling domains) got 401 error. while those users 
in
> : sibling domain can access that IIS box through netbios, etc, just fine.
> : (because there is trust between those domains).
> :
> : any thought on how to get it fixed? any idea are greatly appreciated.
> :
> : thanks.
> :
> : Tao
> :
> :
>
>
>





[ Post a follow-up to this message ]



    Re: IWA with multiple AD  
Ken Schaefer


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
04-23-05 07:50 AM

IIS will automatically check against the domain that it is in (and trusted
domains if the domain is supplied as part of the credentials). Can you post
the relevant IIS logfile entries for the requests in question?

Cheers
Ken

--
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com


"Tao Tao" <TaoTao@discussions.microsoft.com> wrote in message
news:E6E17C5B-2FE3-45ED-9FBA-B2AB5A8CFABC@microsoft.com...
: thanks, Ken.
:
: the site is added in IE as trusted site, so IE automatically grab the
: current AD login and submit them. users are not getting prompted for
: credentials.
:
: How can I configure IIS to check against other AD?
:
: thanks a lot.
:
: Tao
:
: "Ken Schaefer" wrote:
:
: > Are the user's supplying their user-principal-name, or Domain\User as
their
: > username? IIS 6.0 does not check all trusted domains by default.
: >
: > Cheers
: > Ken
: >
: > --
: > Blog: www.adopenstatic.com/cs/blogs/ken/
: > Web: www.adopenstatic.com
: >
: >
: > "Tao Tao" <Tao Tao@discussions.microsoft.com> wrote in message
: > news:7AE1B25E-47B8-444E-A1A7-8CC7F8F96373@microsoft.com...
: > : Hi, have a site on IIS 6.0 configured using IWA only, becaues that
site
: > will
: > : grab user's logon information to keep track it.
: > :
: > : people in same AD with IIS server logon fine with no issues. people in
: > other
: > : AD (same domain tree, sibling domains) got 401 error. while those
users in
: > : sibling domain can access that IIS box through netbios, etc, just
fine.
: > : (because there is trust between those domains).
: > :
: > : any thought on how to get it fixed? any idea are greatly appreciated.
: > :
: > : thanks.
: > :
: > : Tao
: > :
: > :
: >
: >
: >







[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 11:08 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register