Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > september 2005 >

iis security : How do I make iis use domain users on www address


jeff.nospam NO[at]SPAM zina.com
9/5/2005 12:00:00 AM
[quoted text, click to view]

Add the "issuetracker.comp.dk" domain to the intranet zone in IE's
security tab.

Jeff


[quoted text, click to view]
Kim Kragh
9/5/2005 8:25:25 AM
Hi.

I have a general issue where I would like a website to handle both
authenticated and non-authenticated users. I will try to explain further:

The maschine is dt1 (on the domain), the website is vt and the domain is
intranet. From the inside, if authenticated users go to http://dt1/vt they
are on and everything is fine. This website is actually a virtual directory
on the default website.

Now I would like users to use the app (IssueTracker) from home. Here they
are not authenticated and should be prompted for their domain credentials.
The address is issuetracker.comp.dk and they first have to supply
username/password to get nat'ed through the firewall. The firewall redirects
to the IP of dt1.

To catch these request I have set up a new website on dt1 with hostheader.
Same path to the app and same security settings.
I have not tried it from outside yet, but using this new website from the
inside now prompts the already authenticated users? As is it does not
recognize the authenticated users? Is that due to a outsite address
(issuetracker.comp.dk)?
Furthermore, when supplying the credentials, the user is rejected with the
issuetracker.comp.dk/username in the new password prompt. If they replace
issuetracker.comp.dk with intranet, he's in.

So I'm back to Jonathans question: Why is dt1 not using the domain as
default?
I will get back with info of how the thing behaves from the outside.

At last (if still not clear) I would like to have all users use the
issuetracker.comp.dk address and of course; the inside users get right in,
the home users supply their domain credentials (but without intranet\....)

Thanks in advance!

Kim Kragh
9/6/2005 10:03:08 AM
Thanks Jeff

Is that the only way?
I would prefer not to do this on all clients...



[quoted text, click to view]

jeff.nospam NO[at]SPAM zina.com
9/8/2005 12:00:00 AM
[quoted text, click to view]

Don't use Windows Integrated security then. IE doesn't trust a domain
that it doesn't believe is an intranet domain, and won't pass
credentials.

Script out adding the site instead of manually adding it to each
workstation.

Jeff

[quoted text, click to view]
AddThis Social Bookmark Button