Solved

IIS 6 - Windows Authentication to a trusted domain fails

Posted on 2004-10-14
3
3,432 Views
Last Modified: 2012-06-22
I am in the process of deploying sharepoint in an extranet environment.
All external users have an account created on the extranet server (Domain B) and are able to authenticate.

All internal users have accounts on a seperate server (Domain A). I have setup a one-way trust between Domain A and Domain B.

I have added a group on Domain B called "Internal Accounts" and successfully added users from Domain A.

Within the sharepoint portal I have granted "Reader" access to the "Internal Accounts" group.

When an internal user attempts to login, they receive an internal 500 error.
Error Code: -1073740781 (0xc0000413) - Login Failure

If I attempt to login using an account that doesn't exist, I receive an authentication error.
Since I am receiving an Internal 500 error for the problem above, I would assume that Sharepoint does recognize that the user exists, but cannot process some information.

Could this have something to do with the way that Sharepoint impersonates user accounts. Is it possible that even though I have setup the trust, that the impersonated account does not have permission to Domain A's active directory.

Does anyone know if this is a Windows issue I am having or Sharepoint issue?

Many thanks!
0
Comment
Question by:mmcleod1
  • 2
3 Comments
 
LVL 34

Accepted Solution

by:
Dave_Dietz earned 125 total points
ID: 12314074
Sounds like you may actually have a Forest trust rather than a domain trust:

To select the scope of authentication for users authenticating through a forest trust, click the forest trust that you want to administer, and then click Properties. On the Authentication tab, click either Forest-wide authentication or Selective authentication.

With Selective authentication there is additional configuration that needs to take place.

I would suggest using Forest-wide authentication in this case.

See if it helps....  :)

Dave Dietz
0
 

Author Comment

by:mmcleod1
ID: 12323350
Dave, thanks for the suggestion.

Under the Authentication tab, I have an option for Domain-Wide authentication or selective authentication.  (Not Forest-wide authentication)

The trust setup is: domainA.mycompany.net
I have tried adding the trust: mycompany.net and receive the same results.

Any other thoughts?
0
 

Author Comment

by:mmcleod1
ID: 12339035
Well it seems to be working this morning so maybe I just had to be more patient?!?!?
Thanks anyway Dave.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have never ceased to be amazed how many problems you can encounter on a fresh install of a Windows operating system.  This is certainly case in point& Unable to complete ANY MSI installation.  This means Windows Updates are failing and I can't …
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now