?
Solved

Basic Authentication in IIS6 not accepting username/password

Posted on 2006-06-19
6
Medium Priority
?
482 Views
Last Modified: 2012-06-27
We have a remotely hosted dedicated server running Windows Server 2003.  We have a bunch of Virtual Directories setup and for one of them we want to restrict access using Basic Authentication.

When we enable both Integrated and Basic, the login prompt appears as expected and our username/password is accepted.  However, if we disable Integrated (which our client is asking us to do but we don't know why), the Basic Auth prompt appears, we put the same username/password in and it just re-shows the login prompt with the usual 3-strikes and your out result.

We've tried adding a domain name to the HTTP Headers list and then typing this in the defaultdomain field in the ISS properties of the Virtual Directory but it makes no difference.

If we enable the 'allow anonymous' option then the Virtual Directory works fine.  Why not with Basic Auth?

Jay.
0
Comment
Question by:jammy-d0dger
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 
LVL 14

Expert Comment

by:canali
ID: 16937906
Can you report the error  received (401.1   401.2 )?
can u post some line of the log file ?
tried at the auth prompt to enter: nameOfTheServer\username  and password
Gas
0
 

Author Comment

by:jammy-d0dger
ID: 16938231
Hi Canali,

We get this error:
"HTTP Error 401.2 - Unauthorized: Access is denied due to server configuration."

An example of a log entry when auth fails is:
2006-06-19 22:09:54 W3SVC19066 88.xxx.xxx.xxx GET /secureba/ - 80 - 84.xxx.xxx.xxx HTTP/1.1 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1) - - 401 2148074254 1873 327 31

Tried name of server and username... makes no difference :(

Boy I hope you can help... Integrated Auth works fine.... So confused!
0
 

Author Comment

by:jammy-d0dger
ID: 16941143
to anyone that falls foul of Fasthosts Dedicated Servers.... we have solved the issue ourselves:

I don't think you'd have ever guessed the problem as it did indeed turn out to be related to the setup of dedicated servers at Fasthosts.  They have a system called Matrix Control Panel which among other things has a security option on it.  You can enable secure folders through their web-based gui, and it gives you a dialog very similar to the standard challenge/response when you try and browse to a secure folder.  However, it uses it's own ISAPI Filter which is applied at the top level 'Web Sites' properties level.  So even if you haven't got this bespoke security enabled on the domain in question, it is still intercepting any Login attempts.  As soon as we removed the Filter and restarted IIS, the Basic Authentication started working properly.  Many thanks for your initial reply Canali.

I just wanted to share this solution for any other unsuspecting Fasthosts customers.

Case closed.
0
 
LVL 14

Expert Comment

by:canali
ID: 16946571

ok
Bye Gas
0
 
LVL 1

Accepted Solution

by:
DarthMod earned 0 total points
ID: 17160248
PAQed with points refunded (500)

DarthMod
Community Support Moderator
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Learn about cloud computing and its benefits for small business owners.
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question