Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > march 2006 >

iis security : Cannot connect to Web Server from Different Domain


nai
3/27/2006 2:14:02 AM
Hi all,

We have two domains in here and are currently migrating users from Domain A
to Domain B.

We have a trust relationship setup between the two and are using Windows
Integrated Security for Authentication.

My IIS Server is in Domain A.

I can connect to the webserver using User X in Domain A without any problems.
I have created user Y in Domain B with same privileges as X has but I get
prompted to authenticate to the server when I try to connect.
Both Domain Users groups from A and B have access to the server (have been
made members of local Users group).
Currently the only way I have to get this working is to include user Y in
the local Admins group on the server.

Can anyone help - we are in a bit of a pickle !

Cheers.

Roger Abell [MVP]
3/27/2006 7:51:32 AM
That placing user Y in the IIS server's local Administrators group
shows that your problem is completely isolated to what grants are
needed on the IIS server that Y's being only in the Users group of
the IIS server does not grant. You need to review the complete
set of grants made to user X and adjust the grants of Y to be same.

[quoted text, click to view]

nai
3/28/2006 12:01:02 AM
I've just gone through all of the security on the box and it seems that when
the Admin setup the box only some of the permissions were set correctly -
User Y had read/execute permissions on all of the folders under our www root
but not to any of the asp/htm files - i adjusted these/restarted IIS and hey
presto all cool.

Thanks for your help.


[quoted text, click to view]
Roger Abell [MVP]
3/28/2006 5:37:20 AM
That is good. It also sounds like a good example of where
a custom group could/should have been defined and used.

[quoted text, click to view]

AddThis Social Bookmark Button