G
Guest
I'm having problems with some websites I maintain that use Integrated Windows
Authentication for logging in.
The goal is for people to not be prompted for their login information when
they're logged into their laptop using their domain account, and they're on
the LAN. If they're using their corporate laptop and are outside of the
office, I'd prefer that they still don't have to enter in their login info.
Lastly, if they're at a computer that the company doesn't own they should be
prompted for a username and password.
Two of the sites are located on Windows 2003 Servers. One is located on
Windows 2000. All of the sites are setup to use Integrated Windows
Authentication. The sites are using SSL, so people have to use the Fully
Qualified Domain name whether they're on the LAN or outside of our firewall.
The clients are a mix of Windows XP SP2, and Windows 2003 SP1.
I've added two of the sites to the Intranet Zone, and one to the Trusted
Sites Zone in IE on my work laptop. The intranet zone is set to Automatic
logon only in Intranet Zone, and the trusted sites zone is set to Automatic
logon with current username and password. This works great when I'm in the
office. I can get to all 3 sites without being prompted for a username or
password. Unfortunately, when I take my laptop out of the office, and try to
connect to the sites, one of them works, and two cause IE to display "The
page cannot be displayed" "Cannot find server or DNS Error". One of these
problematic sites is in the Intranet zone and is running on 2003, and the
other is in the Trusted Sites zone and is running on 2000. I can ping the
sites, I can run a tracert to the sites, I can even get to the sites if I go
into the security settings for the two zones and set them to Prompt for a
username and password.
Other people with their computers setup exactly the same as mine can't get
to the site that I can get to (they get the same "Cannot find server or DNS
Error"), and again, to work around this issue for those people I tell them to
set their zone to prompt for a password.
In the advanced settings for IE "Show friendly HTTP error messages" is
Un-checked.
It's my understanding that IE will try Integrated windows authentication
first, if that doesn't work it'll fall back on Basic Authentication. This is
what I'd expect would happen if the laptop is outside of the office using a
proxy server, but during my testing I'm just putting my laptop directly on
the internet, no proxy server, and only one firewall between me and all the
sites.
Does anyone know how to fix this problem? I don't think it's an IIS issue
since things work if I just tell IE to prompt for a password, and because the
site that works for me, doesn't work for other people. I also think it's
strange that I get a "Cannot find server or DNS Error" when I can clearly
connect to the server. I'd expect to see a cannot log in error if anything.
Any help would be greatly appreciated. I've been beating my head against
this wall for about two weeks now, with no results other than a major
headache.
Thanks,
Alex.
Authentication for logging in.
The goal is for people to not be prompted for their login information when
they're logged into their laptop using their domain account, and they're on
the LAN. If they're using their corporate laptop and are outside of the
office, I'd prefer that they still don't have to enter in their login info.
Lastly, if they're at a computer that the company doesn't own they should be
prompted for a username and password.
Two of the sites are located on Windows 2003 Servers. One is located on
Windows 2000. All of the sites are setup to use Integrated Windows
Authentication. The sites are using SSL, so people have to use the Fully
Qualified Domain name whether they're on the LAN or outside of our firewall.
The clients are a mix of Windows XP SP2, and Windows 2003 SP1.
I've added two of the sites to the Intranet Zone, and one to the Trusted
Sites Zone in IE on my work laptop. The intranet zone is set to Automatic
logon only in Intranet Zone, and the trusted sites zone is set to Automatic
logon with current username and password. This works great when I'm in the
office. I can get to all 3 sites without being prompted for a username or
password. Unfortunately, when I take my laptop out of the office, and try to
connect to the sites, one of them works, and two cause IE to display "The
page cannot be displayed" "Cannot find server or DNS Error". One of these
problematic sites is in the Intranet zone and is running on 2003, and the
other is in the Trusted Sites zone and is running on 2000. I can ping the
sites, I can run a tracert to the sites, I can even get to the sites if I go
into the security settings for the two zones and set them to Prompt for a
username and password.
Other people with their computers setup exactly the same as mine can't get
to the site that I can get to (they get the same "Cannot find server or DNS
Error"), and again, to work around this issue for those people I tell them to
set their zone to prompt for a password.
In the advanced settings for IE "Show friendly HTTP error messages" is
Un-checked.
It's my understanding that IE will try Integrated windows authentication
first, if that doesn't work it'll fall back on Basic Authentication. This is
what I'd expect would happen if the laptop is outside of the office using a
proxy server, but during my testing I'm just putting my laptop directly on
the internet, no proxy server, and only one firewall between me and all the
sites.
Does anyone know how to fix this problem? I don't think it's an IIS issue
since things work if I just tell IE to prompt for a password, and because the
site that works for me, doesn't work for other people. I also think it's
strange that I get a "Cannot find server or DNS Error" when I can clearly
connect to the server. I'd expect to see a cannot log in error if anything.
Any help would be greatly appreciated. I've been beating my head against
this wall for about two weeks now, with no results other than a major
headache.
Thanks,
Alex.