Groups | Blog | Home
all groups > iis security > december 2003 >

iis security : Access requires password


Brian
12/20/2003 9:39:45 AM
My IIS 6 on Server 2003 worked fine for a month. Then,
all of a sudden, it began prompting for a user ID and
password and no id password combinations worked,
including the admin.

The system had not been touched for 3 days prior to this
beginnning to happen. The logs show a 403.3 and 403.5
errors when trying to access the site.

I have checked NT settings and all the settings on IIS
necessary to get it going, to no avail. In the process, I
changed teh password on IUSR_computername on NT and the
IIM manager.

Any sugestions would be appreciated. Norton has not
detented any virus on this machine.

a-jamur NO[at]SPAM online.microsoft.com
12/21/2003 6:22:27 AM
Hi Brian,

The 403.3 indicates that you have not allowed write access to your
directory and the 403.5 tells us that someone is trying to access your site
wih a client certificate that isn't using 128bit encryption.
403.3 - Write access forbidden.
403.5 - SSL 128 required.
If you are trying to use annonymous authentication make sure your IUSR
account isn't locked out, and that your passwords are synced.


Best regards,
Jason M. Murray [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm.


--------------------
| Content-Class: urn:content-classes:message
| From: "Brian" <bldoss01@acm.org>
| Sender: "Brian" <bldoss01@acm.org>
| Subject: Access requires password
| Date: Sat, 20 Dec 2003 09:39:45 -0800
| Lines: 18
| Message-ID: <014101c3c720$4208cde0$a101280a@phx.gbl>
| MIME-Version: 1.0
| Content-Type: text/plain;
| charset="iso-8859-1"
| Content-Transfer-Encoding: 7bit
| X-Newsreader: Microsoft CDO for Windows 2000
| Thread-Index: AcPHIEII16A4k/5bR8uSW68zJmD1Fg==
| X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
| Newsgroups: microsoft.public.inetserver.iis.security
| Path: cpmsftngxa07.phx.gbl
| Xref: cpmsftngxa07.phx.gbl microsoft.public.inetserver.iis.security:8047
| NNTP-Posting-Host: tk2msftngxa09.phx.gbl 10.40.1.161
| X-Tomcat-NG: microsoft.public.inetserver.iis.security
|
| My IIS 6 on Server 2003 worked fine for a month. Then,
| all of a sudden, it began prompting for a user ID and
| password and no id password combinations worked,
| including the admin.
|
| The system had not been touched for 3 days prior to this
| beginnning to happen. The logs show a 403.3 and 403.5
| errors when trying to access the site.
|
| I have checked NT settings and all the settings on IIS
| necessary to get it going, to no avail. In the process, I
| changed teh password on IUSR_computername on NT and the
| IIM manager.
|
| Any sugestions would be appreciated. Norton has not
| detented any virus on this machine.
|
| Thanks.
|
Brian
12/21/2003 2:17:52 PM
I made a mistake. The logs show 401 3 5 (not 403) for
each attempt to access the site.

How does one check to make sure the IUSR account is not
locket out?

In teh process of trying to get the site accessable over
the past few days, I have changed many setting all over.
In the process, i now cannot access my event viewer for
system and applications. Is there a way to reset all
settings to the original?

Thanks.
[quoted text, click to view]
anonymous NO[at]SPAM discussions.microsoft.com
12/22/2003 8:15:38 AM
Yes, IUSR_Coputername has guest access -- read, read &
execute, write access to the Inetpub/wwwroot folder.

How does one make sure that an account isn't locked
(IUSR_computername)? The system keeps asking for id and
password and none of the id passwords work -- including
the admin id.

Brian
[quoted text, click to view]
Brian
12/22/2003 10:44:04 AM
Yes, IUSR_Coputername has guest access -- read, read &
execute, write access to the Inetpub/wwwroot folder.

How does one make sure that an account isn't locked
(IUSR_computername)? The system keeps asking for id and
password and none of the id passwords work -- including
the admin id.

Brian

[quoted text, click to view]
Bernard
12/22/2003 6:11:39 PM
401.3 - Unauthorized due to ACL on resource.

Check if related user has NTFS permission to access the files/folders.

--
Regards,
Bernard Cheah
http://support.microsoft.com/
Please respond to newsgroups only ...



"Brian" <bldoss01@acm.org> ????
news:01b701c3c810$468cf260$a101280a@phx.gbl...
[quoted text, click to view]

Bernard
12/23/2003 11:43:22 AM
In this case, I would suggest you try filemon and regmon from
sysinternals.com. run in on the server, test browse you site, then trace the
log file to track down any access related errors.

--
Regards,
Bernard Cheah
http://support.microsoft.com/
Please respond to newsgroups only ...



"Brian" <bldoss01@acm.org> ????
news:019501c3c8bb$92bff8c0$a301280a@phx.gbl...
[quoted text, click to view]

a-jamur NO[at]SPAM online.microsoft.com
12/27/2003 6:44:47 AM
Hi,

filemon should tell you is your ACL's error is for IWAM or IUSR.

Best regards,
Jason M. Murray [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm.


--------------------
| From: "Bernard" <qbernard@hotmail.com.discuss>
| References: <014101c3c720$4208cde0$a101280a@phx.gbl>
<EprETr4xDHA.2604@cpmsftngxa07.phx.gbl>
<01b701c3c810$468cf260$a101280a@phx.gbl>
<OT#F7PHyDHA.3216@TK2MSFTNGP11.phx.gbl>
<019501c3c8bb$92bff8c0$a301280a@phx.gbl>
| Subject: Re: Access requires password
| Date: Tue, 23 Dec 2003 11:43:22 +0800
| Lines: 143
| Organization: -
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.3790.0
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
| Message-ID: <uRlVnbQyDHA.2396@TK2MSFTNGP10.phx.gbl>
| Newsgroups: microsoft.public.inetserver.iis.security
| NNTP-Posting-Host: 203.115.210.205
| Path:
cpmsftngxa07.phx.gbl!cpmsftngxa10.phx.gbl!TK2MSFTNGXA05.phx.gbl!TK2MSFTNGP08
.phx.gbl!TK2MSFTNGP10.phx.gbl
| Xref: cpmsftngxa07.phx.gbl microsoft.public.inetserver.iis.security:8083
| X-Tomcat-NG: microsoft.public.inetserver.iis.security
|
| In this case, I would suggest you try filemon and regmon from
| sysinternals.com. run in on the server, test browse you site, then trace
the
| log file to track down any access related errors.
|
| --
| Regards,
| Bernard Cheah
| http://support.microsoft.com/
| Please respond to newsgroups only ...
|
|
|
| "Brian" <bldoss01@acm.org> ????
| news:019501c3c8bb$92bff8c0$a301280a@phx.gbl...
| > Yes, IUSR_Coputername has guest access -- read, read &
| > execute, write access to the Inetpub/wwwroot folder.
| >
| > How does one make sure that an account isn't locked
| > (IUSR_computername)? The system keeps asking for id and
| > password and none of the id passwords work -- including
| > the admin id.
| >
| > Brian
| >
| > >-----Original Message-----
| > >401.3 - Unauthorized due to ACL on resource.
| > >
| > >Check if related user has NTFS permission to access the
| > files/folders.
| > >
| > >--
| > >Regards,
| > >Bernard Cheah
| > >http://support.microsoft.com/
| > >Please respond to newsgroups only ...
| > >
| > >
| > >
| > >"Brian" <bldoss01@acm.org> ????
| > >news:01b701c3c810$468cf260$a101280a@phx.gbl...
| > >> I made a mistake. The logs show 401 3 5 (not 403) for
| > >> each attempt to access the site.
| > >>
| > >> How does one check to make sure the IUSR account is not
| > >> locket out?
| > >>
| > >> In teh process of trying to get the site accessable
| > over
| > >> the past few days, I have changed many setting all
| > over.
| > >> In the process, i now cannot access my event viewer for
| > >> system and applications. Is there a way to reset all
| > >> settings to the original?
| > >>
| > >> Thanks.
| > >> >-----Original Message-----
| > >> >Hi Brian,
| > >> >
| > >> > The 403.3 indicates that you have not allowed write
| > >> access to your
| > >> >directory and the 403.5 tells us that someone is
| > trying
| > >> to access your site
| > >> >wih a client certificate that isn't using 128bit
| > >> encryption.
| > >> >403.3 - Write access forbidden.
| > >> >403.5 - SSL 128 required.
| > >> > If you are trying to use annonymous authentication
| > >> make sure your IUSR
| > >> >account isn't locked out, and that your passwords are
| > >> synced.
| > >> >
| > >> >
| > >> >Best regards,
| > >> >Jason M. Murray [MSFT]
| > >> >This posting is provided "AS IS" with no warranties,
| > and
| > >> confers no rights.
| > >> >Use of included script samples are subject to the
| > terms
| > >> specified at
| > >> >http://www.microsoft.com/info/cpyright.htm.
| > >> >
| > >> >
| > >> >--------------------
| > >> >| Content-Class: urn:content-classes:message
| > >> >| From: "Brian" <bldoss01@acm.org>
| > >> >| Sender: "Brian" <bldoss01@acm.org>
| > >> >| Subject: Access requires password
| > >> >| Date: Sat, 20 Dec 2003 09:39:45 -0800
| > >> >| Lines: 18
| > >> >| Message-ID: <014101c3c720$4208cde0$a101280a@phx.gbl>
| > >> >| MIME-Version: 1.0
| > >> >| Content-Type: text/plain;
| > >> >| charset="iso-8859-1"
| > >> >| Content-Transfer-Encoding: 7bit
| > >> >| X-Newsreader: Microsoft CDO for Windows 2000
| > >> >| Thread-Index: AcPHIEII16A4k/5bR8uSW68zJmD1Fg==
| > >> >| X-MimeOLE: Produced By Microsoft MimeOLE
| > >> V5.50.4910.0300
| > >> >| Newsgroups: microsoft.public.inetserver.iis.security
| > >> >| Path: cpmsftngxa07.phx.gbl
| > >> >| Xref: cpmsftngxa07.phx.gbl
| > >> microsoft.public.inetserver.iis.security:8047
| > >> >| NNTP-Posting-Host: tk2msftngxa09.phx.gbl 10.40.1.161
| > >> >| X-Tomcat-NG:
| > microsoft.public.inetserver.iis.security
| > >> >|
| > >> >| My IIS 6 on Server 2003 worked fine for a month.
| > Then,
| > >> >| all of a sudden, it began prompting for a user ID
| > and
| > >> >| password and no id password combinations worked,
| > >> >| including the admin.
| > >> >|
| > >> >| The system had not been touched for 3 days prior to
| > >> this
| > >> >| beginnning to happen. The logs show a 403.3 and
| > 403.5
| > >> >| errors when trying to access the site.
| > >> >|
| > >> >| I have checked NT settings and all the settings on
| > IIS
| > >> >| necessary to get it going, to no avail. In the
| > >> process, I
| > >> >| changed teh password on IUSR_computername on NT and
| > >> the
| > >> >| IIM manager.
| > >> >|
| > >> >| Any sugestions would be appreciated. Norton has not
| > >> >| detented any virus on this machine.
| > >> >|
| > >> >| Thanks.
| > >> >|
| > >> >
| > >> >.
| > >> >
| > >
| > >
| > >.
| > >
|
|
|
AddThis Social Bookmark Button