Solved

IIS 6 - Windows Authentication to a trusted domain fails

Posted on 2004-10-14
3
3,453 Views
Last Modified: 2012-06-22
I am in the process of deploying sharepoint in an extranet environment.
All external users have an account created on the extranet server (Domain B) and are able to authenticate.

All internal users have accounts on a seperate server (Domain A). I have setup a one-way trust between Domain A and Domain B.

I have added a group on Domain B called "Internal Accounts" and successfully added users from Domain A.

Within the sharepoint portal I have granted "Reader" access to the "Internal Accounts" group.

When an internal user attempts to login, they receive an internal 500 error.
Error Code: -1073740781 (0xc0000413) - Login Failure

If I attempt to login using an account that doesn't exist, I receive an authentication error.
Since I am receiving an Internal 500 error for the problem above, I would assume that Sharepoint does recognize that the user exists, but cannot process some information.

Could this have something to do with the way that Sharepoint impersonates user accounts. Is it possible that even though I have setup the trust, that the impersonated account does not have permission to Domain A's active directory.

Does anyone know if this is a Windows issue I am having or Sharepoint issue?

Many thanks!
0
Comment
Question by:mmcleod1
  • 2
3 Comments
 
LVL 34

Accepted Solution

by:
Dave_Dietz earned 125 total points
ID: 12314074
Sounds like you may actually have a Forest trust rather than a domain trust:

To select the scope of authentication for users authenticating through a forest trust, click the forest trust that you want to administer, and then click Properties. On the Authentication tab, click either Forest-wide authentication or Selective authentication.

With Selective authentication there is additional configuration that needs to take place.

I would suggest using Forest-wide authentication in this case.

See if it helps....  :)

Dave Dietz
0
 

Author Comment

by:mmcleod1
ID: 12323350
Dave, thanks for the suggestion.

Under the Authentication tab, I have an option for Domain-Wide authentication or selective authentication.  (Not Forest-wide authentication)

The trust setup is: domainA.mycompany.net
I have tried adding the trust: mycompany.net and receive the same results.

Any other thoughts?
0
 

Author Comment

by:mmcleod1
ID: 12339035
Well it seems to be working this morning so maybe I just had to be more patient?!?!?
Thanks anyway Dave.
0

Featured Post

Free Webinar: AWS Backup & DR

Join our upcoming webinar with experts from AWS, CloudBerry Lab, and the Town of Edgartown IT to discuss best practices for simplifying online backup management and cutting costs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question