473,769 Members | 4,999 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Kerberos headache

Hi!

I've found an interesting problem that might have something to do with
Kerberos.

I have a www application running in a Windows Server 2003 box. The
server did not have SP1 or SP2 installed. Everything was working
smoothly. Couple days ago we installed SP2 and weird authentication
errors started to occur occasionally.

The webapp is configured to use intergrated authentication ( and
impersonation). It makes calls to a webservice (on the same server) that
allows integrated and basic authentication.

I thought that the whole chain uses NTLM-authentication and Kerberos is
not used at all. Now it seems that sometimes the call from the webapp to
the webservice fails and the security-eventlog shows an failed logon.

Logon Failure:
Reason: An error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Authz
Authentication Package: Kerberos
Workstation Name: MYSERVER
Status code: 0xC000040A
Substatus code: 0x0
Caller User Name: MYSERVER
Caller Domain: MYDOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 828
Transited Services: -
Source Network Address: -
Source Port: -

What is going on? Why only some calls fail and not all? Why did't this
occur with the RTM version?
Tapio

--
*************** *************** *************** *************** ****
Tapio Kulmala

"Those are my principles. If you don't like them I have others."

- Groucho Marx
*************** *************** *************** *************** ****
Feb 1 '08 #1
2 1693
Typical admins can't figure these things out. I'll have to write them
instructions. :(

This customer is a quite small company and they propably don't have many
DC's. Like I said, I'll have to ask them for more details. I'll post
more info here when I get some.

Tapio
Feb 1 '08 #2
Got more information.

The AD is 2000 AD in native mode. All server accounts and user accounts
(in AD) have "Trust computer for delegation" / "Account is trusted for
delegation" set to OFF.
The next question is, why the front end server tries to use the protocol
transition/S4U from Ntlm to Kerberos?

DCs don't support it and accounts are not marked for unconstrained
delegation. The webservice is on the same server so why does it even try
S4USelf? I haven't noticed this kind of behavior with 2003 RTM.

I even checked the C# code. It doesn't do anything too "clever". Just
the usual :

ws.Credentials = System.Net.Cred entialCache.Def aultCredentials ;


Tapio
Feb 4 '08 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
1707
by: Josh T | last post by:
Hi, I'm running Debian Sarge Linux, PHP 4, Apache 2, mod-auth-kerb, PostgreSQL 7.4 on the web server and Windows 2000 Active Directory as the Kerberos server. I want Windows PC users to be able to automatically logon to Apache and PostgreSQL with their Windows usernames/password without any prompts. I can get Apache and mod-auth-kerb to work. I can get the pgsql program to work with Kerberos. However, I need a PHP script already...
0
8180
by: Andreas Schmid | last post by:
Hi, I try to run the example from http://java.sun.com/products/jndi/tutorial/ldap/security/gssapi.html The login on Kerberos succeeds and i get this ticket: Principal: user@MY-DOMAIN.ORG Private Authentisierung: Ticket (hex) = 0000: 61 81 EF 30 81 EC A0 03 02 01 05 A1 0F 1B 0D 4D
1
3030
by: Brian Beck | last post by:
After a bit of searching I haven't been able to find a definite resource for Kerberos authentication from Python. Any help would be appreciated. Here's what I've found... http://starship.python.net/crew/fdrake/manuals/krb5py/krb5py.html This looks all well and good, but the 'original software package' referenced here doesn't work, and as far as I can tell, doesn't even seem to exist (and I do have Handler). The best I could find in...
3
5255
by: Jacob | last post by:
Hello All, I am trying to serve out some content via IIS that is hosted on a remote fileserver, and am unable to get the delegation working correctly. Our setup is as follows: Local LAN Windows 2000 domain (mixed-mode): MYDOMAIN (mydomain.net) Windows 2003 Server w/IIS6: WEB01 Windows 2000 Server hosting files: FILE01 Windows XP Pro client workstation: CLIENT01
0
1534
by: Jasper Pearlman | last post by:
Some documentation on the WSE 2.0 package states that Kerberos support is for Windows Server 2003 and Windows XP SP1 only : "Kerberos token support has been added if you are running on Windows Server 2003 or Windows XP with Service Pack 1, and are running in a Windows Active Directory® network environment that supports Kerberos." Is this speaking to the server-side only? Shouldn't a
1
3853
by: Mark Gibson | last post by:
Hi, I'm having intermittent problems connecting to my PostgreSQL database from PHP, using Kerberos credentials forwarded from mod_auth_kerb. - User authenticates via mod_auth_kerb, (either Basic or Negotiate HTTP authenication) - Kerberos credentials are stored in a file that lives for the lifetime of the HTTP connection.
0
2315
by: CESAR DE LA TORRE [MVP] | last post by:
I am using WSE 3.0 with Visual Studio 2005, specifically I'm using Kerberos authentication and passing Kerberos ticket from Presentation Tier (VSTO.2005 client) to Server Tier through our Web Services (based on WSE 3.0). Having our WSE 3.0-WebService over Windows Server 2003, everything works great, but, over Windows XP, I have a problem (which is documented in WSE 3.0 help) but its workaround does not work properly (at least with my...
1
2730
by: russell.lane | last post by:
I've established user login identity impersonation and delegation for a multi-tier web application. I'm running into a case where authentication fails when a user accesses the app from a browser on one machine, but not from another machine. The relevant details -- in both cases, all of the following are in effect: Same user account. Same web application, same IIS host. Client OS is XP Pro SP2.
4
7390
by: webrod | last post by:
Hi, I am trying to secure a WS using WSE 3.0 and kerberos. I used the "WSE 3.0 settings" from VS2005 with my own WS. I have a console application which try to access a WS. With the following configuration it works: - WS/IIS and AD on the Windows 2003 server - console application on a Windows XP workstation
0
9589
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
9423
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
0
10211
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
0
10045
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth. The Art of Business Website Design Your website is...
0
9863
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
0
8872
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
0
6673
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
5299
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
3
2815
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating effective websites that not only look great but also perform exceptionally well. In this comprehensive...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.