Integrated authentication across domains
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > Integrated authentication across domains




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Integrated authentication across domains  
jonas.berling@knowit.se


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
11-16-07 06:39 PM

Hi!

Our intranet is running IIS6 on Win2k3 and is using Windows Integrated
Authentication without SSL. It is working perfectly as long as the
users are on the same domain as the server.

The company has opened a new office abroad and staff from this office
are on a different domain. We would now want them to be able to access
our intranet over some leased lines and we have opened up the
firewalls accordingly. The users abroad are running IE6 and their IT
admin has set our domain into their browser's intranet zone.

The users can contact the server and are prompted for their login and
password and that's how it should be. They enter <Domain>\Login and
their password and press enter. The strange thing is that now nothing
more happens. The browsers appear to be loading some data but nothing
appears on the screen, it just stays white. There is no error message
and there is nothing in netiher the servers event log nor its web
server log and it just stays like this "forever". The user's browser
says "intranet" in the bottom right corner, so it appears to got that
one straight.

What could be the problem? Do we have to use SSL? Could it be some
strange setup in the firewalls - the web server is on port 80 and that
is what is opened in the firewalls. Suggestions, anyone?


Regards,

Jonas






[ Post a follow-up to this message ]



    Re: Integrated authentication across domains  
DaveMo


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
11-16-07 06:39 PM

On Nov 8, 1:16 pm, jonas.berl...@knowit.se wrote:
> Hi!
>
> Our intranet is running IIS6 on Win2k3 and is using Windows Integrated
> Authentication without SSL. It is working perfectly as long as the
> users are on the same domain as the server.
>
> The company has opened a new office abroad and staff from this office
> are on a different domain. We would now want them to be able to access
> our intranet over some leased lines and we have opened up the
> firewalls accordingly. The users abroad are running IE6 and their IT
> admin has set our domain into their browser's intranet zone.
>
> The users can contact the server and are prompted for their login and
> password and that's how it should be. They enter <Domain>\Login and
> their password and press enter. The strange thing is that now nothing
> more happens. The browsers appear to be loading some data but nothing
> appears on the screen, it just stays white. There is no error message
> and there is nothing in netiher the servers event log nor its web
> server log and it just stays like this "forever". The user's browser
> says "intranet" in the bottom right corner, so it appears to got that
> one straight.
>
> What could be the problem? Do we have to use SSL? Could it be some
> strange setup in the firewalls - the web server is on port 80 and that
> is what is opened in the firewalls. Suggestions, anyone?
>
> Regards,
>
> Jonas

Hello Jonas,

What domain are they using when the user types their creds? Their
domain or the domain of the resource? Is there a trust established
between the domains?

I would use netmon and see what is going on at the network layer. This
doesn't sound like any kind of behavior I've ever seen that could be
caused by an authentication issue.

HTH,
Dave






[ Post a follow-up to this message ]



    Re: Integrated authentication across domains  
Consultant


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
11-16-07 06:39 PM

you have to open the ports on your firewall to allow the credentials to be
passed thru

<jonas.berling@knowit.se> wrote in message
news:1194556583.948283.53070@v23g2000prn.googlegroups.com...
> Hi!
>
> Our intranet is running IIS6 on Win2k3 and is using Windows Integrated
> Authentication without SSL. It is working perfectly as long as the
> users are on the same domain as the server.
>
> The company has opened a new office abroad and staff from this office
> are on a different domain. We would now want them to be able to access
> our intranet over some leased lines and we have opened up the
> firewalls accordingly. The users abroad are running IE6 and their IT
> admin has set our domain into their browser's intranet zone.
>
> The users can contact the server and are prompted for their login and
> password and that's how it should be. They enter <Domain>\Login and
> their password and press enter. The strange thing is that now nothing
> more happens. The browsers appear to be loading some data but nothing
> appears on the screen, it just stays white. There is no error message
> and there is nothing in netiher the servers event log nor its web
> server log and it just stays like this "forever". The user's browser
> says "intranet" in the bottom right corner, so it appears to got that
> one straight.
>
> What could be the problem? Do we have to use SSL? Could it be some
> strange setup in the firewalls - the web server is on port 80 and that
> is what is opened in the firewalls. Suggestions, anyone?
>
>
> Regards,
>
> Jonas
>







[ Post a follow-up to this message ]



    Re: Integrated authentication across domains  
Roger Abell [MVP]


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
11-16-07 06:39 PM

Let's assume these domains are in one forest.
The IIS machine needs to be able to contact the domain controllers
of the account domain in order to authenticate the requestor.
Are you leveraging the Windows security event log to help you
see what is (not) happening?

<jonas.berling@knowit.se> wrote in message
news:1194556583.948283.53070@v23g2000prn.googlegroups.com...
> Hi!
>
> Our intranet is running IIS6 on Win2k3 and is using Windows Integrated
> Authentication without SSL. It is working perfectly as long as the
> users are on the same domain as the server.
>
> The company has opened a new office abroad and staff from this office
> are on a different domain. We would now want them to be able to access
> our intranet over some leased lines and we have opened up the
> firewalls accordingly. The users abroad are running IE6 and their IT
> admin has set our domain into their browser's intranet zone.
>
> The users can contact the server and are prompted for their login and
> password and that's how it should be. They enter <Domain>\Login and
> their password and press enter. The strange thing is that now nothing
> more happens. The browsers appear to be loading some data but nothing
> appears on the screen, it just stays white. There is no error message
> and there is nothing in netiher the servers event log nor its web
> server log and it just stays like this "forever". The user's browser
> says "intranet" in the bottom right corner, so it appears to got that
> one straight.
>
> What could be the problem? Do we have to use SSL? Could it be some
> strange setup in the firewalls - the web server is on port 80 and that
> is what is opened in the firewalls. Suggestions, anyone?
>
>
> Regards,
>
> Jonas
>







[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 08:10 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register