Kerberos only works with certain DNS entries (IIS Website)


have odd , frustrating issue using kerberos authentication iis site.
works form hostnames, not others (and it's not obvious!)
i've tried provide info can.
i've detailed environment first, , detail issue.

environment configuration:
secure development environment intranet.
windows server 2012r2 iis 8
2 ad controllers
dedicated domain - devdomain.co.uk
there no proxy servers or firewalls between of servers or client pc - it's virtual dev platform.

webserver - devcms1 - running single website
windows authentication enabled - else disabled
providers configured negotiate ntlm
kernel mode authentication enabled
website app pool running under domain account - cmsapppool
website has following bindings - 
hostname=any ip=all unassigned port=80
hostname=cms.devdomain.co.uk ip=all unassigned port=80

there dns (a record) entry cms.devdomain.co.uk resolves ip of webserver

client pc win 7, member of domain
internet explorer configured url's in local intranet zone
enable integrated windows authentication enabled.

following spn commands have been run
setspn -s http/devcms1 devdomain\cmsapppool
setspn -s http/devcms1.devdomain.co.uk devdomain\cmsapppool
setspn -s http/cms.devdomain.co.uk devdomain\cmsapppool

there no duplicate spn's - confirmed using spnhelper script

scenarios , problem:
if browse http://devcms1 automatically logged in , kerberos being used  - confirmed fiddler , wireshark
if browse http://devcms1.devdomain.co.uk automatically logged in , kerberos being used - confirmed fiddler , wireshark
if browse http://cms.devdomain.co.uk receive log in prompt despite entering correct credentials results in an access denied after 3 attempts. fiddler , wireshark show kerberos being used.
above url's resolve same webserver , website. url's in local intranet zone in ie.

cannot understand why last scenario fails - why not work specific dns entry (one isn't automatically derived machine name).

have followed steps given in article - http://support2.microsoft.com/kb/929650

advice gratefully received @ wits end.

thanks

jason

hi jason,

looks there wrong web site configuration, suggest refer experts iis forum more efficient support:

http://forums.iis.net/

best regards,

amy



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...