Groups | Blog | Home
all groups > iis security > december 2007 >

iis security : Stumped by Authentication Problem


SirCodesALot
12/4/2007 1:38:38 PM
Hi All,

I am stuck and could use some help. For some reason, none of our
domain users can access our webpages unless they are added to the
Administrator group on the Web server and I can't figure out why. This
just started happening recently.

We have a local group called Users that conains our Domain Users.

Here is what I have done:

1. Checked that the users gruops has access to the Web Directory -
Users - yes
IIS_WFG - yes
System - yes
Administrators - yes
Users - yes

2. Checked the authentication method for the Website
- Integrated Windows Authentication

3. Looked at the logs for a persons not in the Adminstrators groups.
Here are a few lines:
2007-12-04 21:28:28 W3SVC1786339847 GET /ts/index.html - 80 - 401
1 0
2007-12-04 21:28:28 W3SVC1786339847 GET /ts/index.html - 80 - 500
0 2148074244

So it looks like it is failing because it can't validate the user and
only works if the user is in the admin group. Anyone have any idea
why?

Thanks in advance for your help!
-SJ
SirCodesALot
12/5/2007 9:05:48 AM
On Dec 5, 4:02 am, "Ken Schaefer" <kenREM...@THISadOpenStatic.com>
[quoted text, click to view]

Ken, thanks for your response! I will try looking into that way.

Thanks again,
Ken Schaefer
12/5/2007 9:02:58 PM
Hi,

This isn't an IIS issue - something is happening lower down in the stack
(e.g. inside LSASS or similar).

The initial request is denied with an Unauthorized (401) HTTP status. The
client then appears to be sending credentials, and the server is returning
500. The Win32 status indicates an internal security error occurred.

I would start by looking in the Windows Event Logs to see if any errors are
being logged there.

Cheers
Ken


--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken


[quoted text, click to view]
Roger Abell [MVP]
12/6/2007 11:50:39 PM
[quoted text, click to view]

Indeed Ken, and might not the app trace be useful too, as it seems
by 500 that it is not handling the (unanticipated?) access denial.

Roger

[quoted text, click to view]

Roger Abell [MVP]
12/6/2007 11:57:14 PM
So this means you have looked in the event logs, and there seen
these domain users members successful at login, yet they are
denied access to the resource. Right? . . . or at least no failed
login events for them then if you don't log success?

If not so, was there a change in login rights, or in group nestings
recently?

Roger

[quoted text, click to view]

Ken Schaefer
12/8/2007 10:18:37 PM

[quoted text, click to view]

It could be, but Win32 error 2148074244 is SEC_E_INTERNAL_ERROR, which
indicates to me tha there is an error below IIS. IIS is then seeing this not
as an access denied, but some other error it is not equiped to handle, and
so IIS generates the 500 Internal Server Error, not the application. The
application probably isn't seeing the request at all

Cheers
Ken


[quoted text, click to view]
THKS
12/17/2007 1:30:52 PM
Check whether you have the correct user group settings under logon locally
right on server security policy.

[quoted text, click to view]
AddThis Social Bookmark Button