Kerberos only works with certain DNS entries (IIS Website)
have odd , frustrating issue using kerberos authentication iis site.
works form hostnames, not others (and it's not obvious!)
i've tried provide info can.
i've detailed environment first, , detail issue.
environment configuration:
secure development environment intranet.
windows server 2012r2 iis 8
2 ad controllers
dedicated domain - devdomain.co.uk
there no proxy servers or firewalls between of servers or client pc - it's virtual dev platform.
webserver - devcms1 - running single website
windows authentication enabled - else disabled
providers configured negotiate ntlm
kernel mode authentication enabled
website app pool running under domain account - cmsapppool
website has following bindings -
hostname=any ip=all unassigned port=80
hostname=cms.devdomain.co.uk ip=all unassigned port=80
there dns (a record) entry cms.devdomain.co.uk resolves ip of webserver
client pc win 7, member of domain
internet explorer configured url's in local intranet zone
enable integrated windows authentication enabled.
following spn commands have been run
setspn -s http/devcms1 devdomain\cmsapppool
setspn -s http/devcms1.devdomain.co.uk devdomain\cmsapppool
setspn -s http/cms.devdomain.co.uk devdomain\cmsapppool
there no duplicate spn's - confirmed using spnhelper script
scenarios , problem:
if browse http://devcms1 automatically logged in , kerberos being used - confirmed fiddler , wireshark
if browse http://devcms1.devdomain.co.uk automatically logged in , kerberos being used - confirmed fiddler , wireshark
if browse http://cms.devdomain.co.uk receive log in prompt despite entering correct credentials results in an access denied after 3 attempts. fiddler , wireshark show kerberos being used.
above url's resolve same webserver , website. url's in local intranet zone in ie.
cannot understand why last scenario fails - why not work specific dns entry (one isn't automatically derived machine name).
have followed steps given in article - http://support2.microsoft.com/kb/929650
advice gratefully received @ wits end.
thanks
jason
works form hostnames, not others (and it's not obvious!)
i've tried provide info can.
i've detailed environment first, , detail issue.
environment configuration:
secure development environment intranet.
windows server 2012r2 iis 8
2 ad controllers
dedicated domain - devdomain.co.uk
there no proxy servers or firewalls between of servers or client pc - it's virtual dev platform.
webserver - devcms1 - running single website
windows authentication enabled - else disabled
providers configured negotiate ntlm
kernel mode authentication enabled
website app pool running under domain account - cmsapppool
website has following bindings -
hostname=any ip=all unassigned port=80
hostname=cms.devdomain.co.uk ip=all unassigned port=80
there dns (a record) entry cms.devdomain.co.uk resolves ip of webserver
client pc win 7, member of domain
internet explorer configured url's in local intranet zone
enable integrated windows authentication enabled.
following spn commands have been run
setspn -s http/devcms1 devdomain\cmsapppool
setspn -s http/devcms1.devdomain.co.uk devdomain\cmsapppool
setspn -s http/cms.devdomain.co.uk devdomain\cmsapppool
there no duplicate spn's - confirmed using spnhelper script
scenarios , problem:
if browse http://devcms1 automatically logged in , kerberos being used - confirmed fiddler , wireshark
if browse http://devcms1.devdomain.co.uk automatically logged in , kerberos being used - confirmed fiddler , wireshark
if browse http://cms.devdomain.co.uk receive log in prompt despite entering correct credentials results in an access denied after 3 attempts. fiddler , wireshark show kerberos being used.
above url's resolve same webserver , website. url's in local intranet zone in ie.
cannot understand why last scenario fails - why not work specific dns entry (one isn't automatically derived machine name).
have followed steps given in article - http://support2.microsoft.com/kb/929650
advice gratefully received @ wits end.
thanks
jason
hi jason,
looks there wrong web site configuration, suggest refer experts iis forum more efficient support:
best regards,
amy
Windows Server > Directory Services
Comments
Post a Comment