Groups | Blog | Home
all groups > iis security > july 2006 >

iis security : Integrated Windows Authentication results in -2146893052 (0x80090304)


mmichaels
7/18/2006 11:39:05 PM
I have a website on Windows 2000 server with only IWA enabled. I can
log into the site just fine, but if I type a bad password I get an HTTP
500 error. I can't figure out why I'm not reprompted for the password
at least another time or two.

I turned off "friendly errors" in IE and I now get -2146893052
(0x80090304) (also get the same in Firefox).

My local policy effective setting for "cached passwords" is set to 10.

Can anybody shed some light on why I'm only prompted for a password
once?

Marc
mmichaels
7/19/2006 8:30:20 PM
Hi Ken,

Your lead on LSASS should be helpful. All I'm getting is a failure in
the security log:


Source: Security
Category: Logon/Logoff
Type: failure
Event ID: 537
User: NT AUTHORITY\SYSTEM
Computer: MYIISCOMPUTERNAME

Logon Failure:
Reason: An unexpected error occurred during logon
User Name: myuser@mydomain.com
Domain:
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: ITDIRECTOR

Also the mydomain.com is an OU that is nested within my root domain.
Ken Schaefer
7/20/2006 12:00:00 AM
And there is nothing useful in the System or Application event logs?

Cheers
Ken


[quoted text, click to view]

Ken Schaefer
7/20/2006 12:00:00 AM
Err 0x80090304
Local Security Authority could not be contacted

Seems IIS has a problem talking to LSASS, which would also explain why you
are not prompted again. Is there anything in the Windows Event Logs that
might help troubleshoot the problem?

Cheers
Ken

[quoted text, click to view]

AddThis Social Bookmark Button