Click here to get back home

Weird Behaviour Accessing MS CA Web Site

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Weird Behaviour Accessing MS CA Web Site Hilding 08-04-2008
Get Chitika Premium
Posted by Hilding on August 4, 2008, 4:44 pm
Please log in for more thread options
I'm accessing the Certsrv pages from a Windows XP client, the CA is
Win2K3 Enterprise. If I access it using FQDN or NETBIOS I get a basic
challenge - and even with the correct credentials I can't logon (after
clicking OK in the basic prompt it just re-appears again). If I
access it using IP-Address, I get a basic challenge and I can access
the site.

Strange thing is, I've tried adding FQDN and NETBIOS into intranet
zone, but it doesn't change the behaviour; using the IP address relies
on the Internet zone.

On the CA itself, I can access certsrv using NETBIOS or IP address,
entering FQDN gives me a basic prompt and the same problem described
above.

I originally had the problems on IE6, so I upgraded to IE7 but the
problems are exactly the same.

Anyone had any similar problems with certsrv? Any ideas?

Posted by Hilding on August 4, 2008, 5:50 pm
Please log in for more thread options
I meant to say, that when on the CA itself and I use NETBIOS or IP-
address I go straight in to Certsrv, i.e. I don't get the basic prompt.

Posted by Roger Abell [MVP] on August 5, 2008, 2:37 am
Please log in for more thread options
> I'm accessing the Certsrv pages from a Windows XP client, the CA is
> Win2K3 Enterprise. If I access it using FQDN or NETBIOS I get a basic
> challenge - and even with the correct credentials I can't logon (after
> clicking OK in the basic prompt it just re-appears again). If I
> access it using IP-Address, I get a basic challenge and I can access
> the site.
>
> Strange thing is, I've tried adding FQDN and NETBIOS into intranet
> zone, but it doesn't change the behaviour; using the IP address relies
> on the Internet zone.
>
> On the CA itself, I can access certsrv using NETBIOS or IP address,
> entering FQDN gives me a basic prompt and the same problem described
> above.
>
> I originally had the problems on IE6, so I upgraded to IE7 but the
> problems are exactly the same.
>
> Anyone had any similar problems with certsrv? Any ideas?

When you use IP you are forcing that Kerberos not be used.
Perhaps NTLM authentication is successful but when accessing other
than by IP Kerberos is result from the auth negotiation but then the login
via Kerberos is failing. Have you examined the security event log if it
is configured to record login failures?



Similar ThreadsPosted
NTLM Auth (weird) January 23, 2008, 4:15 pm
Weird Processes on my Windows 2003 Servers July 16, 2006, 9:43 am
Weird problem with an ASP.NET application and Session Variables that mess up July 7, 2005, 10:34 am
Site Deployments August 8, 2005, 8:56 am
building a web site January 26, 2006, 8:34 pm
New ISA Server site: www.ISAscripts.org August 17, 2005, 12:00 pm
cannot access a secure web site September 27, 2005, 1:15 pm
machine authentication for web site? February 21, 2006, 10:09 am
Network/Web Site Authentication July 25, 2006, 9:31 am
FTP site on ADC creating problems!!!! June 21, 2008, 11:49 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap