Advertisement

02.28.2008 at 05:16PM PST, ID: 23202582
[x]
Attachment Details

Troubleshooting authentication errors

Asked by diegoslice in Microsoft IIS Web Server, Windows 2003 Server

Tags: Microsoft, Windows 2003 / IIS 6, Behind firewall / no proxy

I am struggling to find the root cause of an authentication issue. I have tested in both IE7 and Firefox 2 with similar results so this issue is not browser specific.

The setup is probably pretty typical of most enterprise configurations. There is a Cisco firewall in front, and three servers behind it - a domain server, a web server and a MS SQL Server.

Accessing the web site requires a PKI certificate. Once the certificate is verified, a user is authenticated using Windows authentication / NTLM to a domain server using a DOMAIN\username and password.

Now the problem is that after a user is authenticated and browsing the web site, they seem to lose their authentication. In the browser, a link is clicked and nothing happens for about 10 minutes until another authentication prompt pops up. Filling in the prompt makes it go away for another 10 minutes until it pops back up and so on.

In the IIS web logs (see attached file), a user clearly loses authenticated status. The last seven lines of the log show that I when I clicked on the /product/switch.asp page from the webtools.asp page, IIS forced the request back to the site's default home page (default1.asp) and issued a 403 7 64 error. The sc-win32-status of 64 indicates "The specified network name is no longer available", ERROR_NETNAME_DELETED (see http://help.netop.com/support/errorcodes/win32_error_codes.htm) and the 403.7 error indicates a client certificate is required.

The final six lines show the browser trying to fetch the /product/switch.asp three times (10 minute timeout between) and getting a 401 2 2148074254 (what does a sc-win32-status of 2148074254 mean?) followed by a 401 1 0. Since the graphic files have the same pattern and loaded fine, I am more inclined to question why the 403.7 error occurred and what prevents the browser from recovering. If I completely close the browser, I can usually log back in and fetch the file without problem until some other random time in the future.

The other file attached is the logman IIS trace file. If you open the file and search for 'Request n.54', that is the start of the last good request for favorite.gif. 'Request n.55' is for the failed product/switch.asp file. Note that the IIS logman trace and the IIS web log file don't match up in that the web log shows the 403 7 64 error for the default1.asp page right after favorite.gif was requested. The logman trace also shows that request 55 (first attempt for switch.asp) authenticated me but then seems to end with four of the following:

AspReq: ASP_END_CACHE_ACCESS - Check Cache End
    ErrorCode: 0x00000000
    AccessResult: SERVED_CACHE_HIT_CHANGENOTIF
    ContextIDSeq: 55
    Timestamp: 18:50:38.131.733400

Now most requests end with 'IISGeneral: GENERAL_REQUEST_END - IIS ends processing a request' and the logman trace was left on for another half hour so it is not like I cut the trace off before the request had finished. Note that nowhere is a redirection to default1.asp shown so not sure how IIS put that in the log file.

After reviewing this info, I don't feel any closer to a solution. Has anyone else seen anything similar?

I should also state that my domain login is in the local administrators group and the admin group, users group and IUSR_ account all have read access to the file so I doubt it is ACL related.
Start Free Trial
Attachments:
 
IIS log file ending in user unauthenticated
 
 
logman IIS trace file for IIS providers matching up to log file
 
[+][-]02.28.2008 at 05:48PM PST, ID: 21009985

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.28.2008 at 06:26PM PST, ID: 21010213

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.28.2008 at 06:30PM PST, ID: 21010229

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 01:49AM PST, ID: 21011975

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 01:58AM PST, ID: 21012003

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:22AM PST, ID: 21016019

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:29AM PST, ID: 21016099

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:58AM PST, ID: 21016376

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 02:47AM PST, ID: 21039752

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 10:20AM PST, ID: 21043480

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 12:11PM PST, ID: 21044581

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 01:20PM PST, ID: 21045230

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 02:11PM PST, ID: 21045668

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Microsoft IIS Web Server, Windows 2003 Server
Tags: Microsoft, Windows 2003 / IIS 6, Behind firewall / no proxy
Sign Up Now!
Solution Provided By: miqrogroove
Participating Experts: 3
Solution Grade: B
 
 
[+][-]06.02.2008 at 04:56PM PDT, ID: 21696739

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628