all groups > iis security > april 2005 >
You're in the

iis security

group:

IWA with multiple AD



IWA with multiple AD Tao Tao
4/21/2005 1:52:02 PM
iis security: Hi, have a site on IIS 6.0 configured using IWA only, becaues that site will
grab user's logon information to keep track it.

people in same AD with IIS server logon fine with no issues. people in other
AD (same domain tree, sibling domains) got 401 error. while those users in
sibling domain can access that IIS box through netbios, etc, just fine.
(because there is trust between those domains).

any thought on how to get it fixed? any idea are greatly appreciated.

thanks.

Tao

Re: IWA with multiple AD Ken Schaefer
4/22/2005 12:00:00 AM
Are the user's supplying their user-principal-name, or Domain\User as their
username? IIS 6.0 does not check all trusted domains by default.

Cheers
Ken

--
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com


[quoted text, click to view]
: Hi, have a site on IIS 6.0 configured using IWA only, becaues that site
will
: grab user's logon information to keep track it.
:
: people in same AD with IIS server logon fine with no issues. people in
other
: AD (same domain tree, sibling domains) got 401 error. while those users in
: sibling domain can access that IIS box through netbios, etc, just fine.
: (because there is trust between those domains).
:
: any thought on how to get it fixed? any idea are greatly appreciated.
:
: thanks.
:
: Tao
:
:

Re: IWA with multiple AD Tao Tao
4/22/2005 7:39:15 AM
thanks, Ken.

the site is added in IE as trusted site, so IE automatically grab the
current AD login and submit them. users are not getting prompted for
credentials.

How can I configure IIS to check against other AD?

thanks a lot.

Tao

[quoted text, click to view]
Re: IWA with multiple AD Ken Schaefer
4/23/2005 12:00:00 AM
IIS will automatically check against the domain that it is in (and trusted
domains if the domain is supplied as part of the credentials). Can you post
the relevant IIS logfile entries for the requests in question?

Cheers
Ken

--
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com


[quoted text, click to view]
: thanks, Ken.
:
: the site is added in IE as trusted site, so IE automatically grab the
: current AD login and submit them. users are not getting prompted for
: credentials.
:
: How can I configure IIS to check against other AD?
:
: thanks a lot.
:
: Tao
:
[quoted text, click to view]
:
: > Are the user's supplying their user-principal-name, or Domain\User as
their
: > username? IIS 6.0 does not check all trusted domains by default.
: >
: > Cheers
: > Ken
: >
: > --
: > Blog: www.adopenstatic.com/cs/blogs/ken/
: > Web: www.adopenstatic.com
: >
: >
[quoted text, click to view]
: > : Hi, have a site on IIS 6.0 configured using IWA only, becaues that
site
: > will
: > : grab user's logon information to keep track it.
: > :
: > : people in same AD with IIS server logon fine with no issues. people in
: > other
: > : AD (same domain tree, sibling domains) got 401 error. while those
users in
: > : sibling domain can access that IIS box through netbios, etc, just
fine.
: > : (because there is trust between those domains).
: > :
: > : any thought on how to get it fixed? any idea are greatly appreciated.
: > :
: > : thanks.
: > :
: > : Tao
: > :
: > :
: >
: >
: >

AddThis Social Bookmark Button