Advertisement

02.28.2008 at 05:16PM PST, ID: 23202582
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

8.4

Troubleshooting authentication errors

Asked by diegoslice in Microsoft IIS Web Server, Windows 2003 Server

Tags: , ,

I am struggling to find the root cause of an authentication issue. I have tested in both IE7 and Firefox 2 with similar results so this issue is not browser specific.

The setup is probably pretty typical of most enterprise configurations. There is a Cisco firewall in front, and three servers behind it - a domain server, a web server and a MS SQL Server.

Accessing the web site requires a PKI certificate. Once the certificate is verified, a user is authenticated using Windows authentication / NTLM to a domain server using a DOMAIN\username and password.

Now the problem is that after a user is authenticated and browsing the web site, they seem to lose their authentication. In the browser, a link is clicked and nothing happens for about 10 minutes until another authentication prompt pops up. Filling in the prompt makes it go away for another 10 minutes until it pops back up and so on.

In the IIS web logs (see attached file), a user clearly loses authenticated status. The last seven lines of the log show that I when I clicked on the /product/switch.asp page from the webtools.asp page, IIS forced the request back to the site's default home page (default1.asp) and issued a 403 7 64 error. The sc-win32-status of 64 indicates "The specified network name is no longer available", ERROR_NETNAME_DELETED (see http://help.netop.com/support/errorcodes/win32_error_codes.htm) and the 403.7 error indicates a client certificate is required.

The final six lines show the browser trying to fetch the /product/switch.asp three times (10 minute timeout between) and getting a 401 2 2148074254 (what does a sc-win32-status of 2148074254 mean?) followed by a 401 1 0. Since the graphic files have the same pattern and loaded fine, I am more inclined to question why the 403.7 error occurred and what prevents the browser from recovering. If I completely close the browser, I can usually log back in and fetch the file without problem until some other random time in the future.

The other file attached is the logman IIS trace file. If you open the file and search for 'Request n.54', that is the start of the last good request for favorite.gif. 'Request n.55' is for the failed product/switch.asp file. Note that the IIS logman trace and the IIS web log file don't match up in that the web log shows the 403 7 64 error for the default1.asp page right after favorite.gif was requested. The logman trace also shows that request 55 (first attempt for switch.asp) authenticated me but then seems to end with four of the following:

AspReq: ASP_END_CACHE_ACCESS - Check Cache End
    ErrorCode: 0x00000000
    AccessResult: SERVED_CACHE_HIT_CHANGENOTIF
    ContextIDSeq: 55
    Timestamp: 18:50:38.131.733400

Now most requests end with 'IISGeneral: GENERAL_REQUEST_END - IIS ends processing a request' and the logman trace was left on for another half hour so it is not like I cut the trace off before the request had finished. Note that nowhere is a redirection to default1.asp shown so not sure how IIS put that in the log file.

After reviewing this info, I don't feel any closer to a solution. Has anyone else seen anything similar?

I should also state that my domain login is in the local administrators group and the admin group, users group and IUSR_ account all have read access to the file so I doubt it is ACL related.
Start Free Trial
Attachments:
 
IIS log file ending in user unauthenticated
 
 
logman IIS trace file for IIS providers matching up to log file
 
[+][-]02.28.2008 at 05:48PM PST, ID: 21009985

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.28.2008 at 06:26PM PST, ID: 21010213

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.28.2008 at 06:30PM PST, ID: 21010229

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 01:49AM PST, ID: 21011975

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 01:58AM PST, ID: 21012003

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:22AM PST, ID: 21016019

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:29AM PST, ID: 21016099

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.29.2008 at 10:58AM PST, ID: 21016376

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 02:47AM PST, ID: 21039752

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 10:20AM PST, ID: 21043480

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 12:11PM PST, ID: 21044581

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 01:20PM PST, ID: 21045230

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.04.2008 at 02:11PM PST, ID: 21045668

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Microsoft IIS Web Server, Windows 2003 Server
Tags: Microsoft, Windows 2003 / IIS 6, Behind firewall / no proxy
Sign Up Now!
Solution Provided By: miqrogroove
Participating Experts: 3
Solution Grade: B
 
 
[+][-]06.02.2008 at 04:56PM PDT, ID: 21696739

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20081112-EE-VQP-44 / EE_QW_2_20070628