Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1569
  • Last Modified:

RPC over https login failing - HTTP Error 401.3

I have a new 2003 single server exchange install. I am having no luck with RPC over https.
The server is installed in a the site domain with a seperater domain controller in each site.
the site with exchange has
mx1.domain.local - exhcange server
dc2.domain.local - domain controller (dns)

I have followed a heap of guides the only one that talks of RPC in a single exchange server - with a seperate dc.
http://www.amset.info/exchange/rpc-http-server.asp

In particular he mentions including the dc in the Validports entry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\RpcProxy

In IIS I have set the rpc directory security - authentication to  basic and the default domain to domain.local

Anyway now to the problem
When I test the server in a browser on the LAN or the wan eg https://mx1/rpc
I get a prompt for a username and password however authentication is unsuccsessfull after three attempts I recieve a "HTTP Error 401.3"

I have tried a world of username password combinations with no luck.

owa is working fine externally.

Any ideas welcome.
0
btomkins
Asked:
btomkins
  • 5
  • 2
  • 2
1 Solution
 
SembeeCommented:
Authentication failure on the /rpc virtual directory is normal. The test is to see if you get a certificate prompt or not.
You need to move on to the Outlook configuration. Using a normal domain client already configured for Exchange access (and working) add the addition settings for RPC over HTTPS. Restart Outlook and see what happens.

Simon.
0
 
btomkinsAuthor Commented:
RPCdump has some access denied errors

dc2.domain.local has had the registry fix

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters

Type REG_MULTI_SZ
Name: NSPI Interface protocol sequences
Value: ncacn_http:6004


I notice
UUID:1544f5e0-613c-11d1-93df-00c04fd7bd09
how can I tell what server this is?
Thanks
Brian
========================================================
Querying Endpoint Mapper Database...

149 registered endpoints found.


Collecting Data....  This may take a while.

          0    10   20   30   40   50   60   70   80   90  100
          |----|----|----|----|----|----|----|----|----|----|
          ...................................................

ProtSeq:ncacn_http

Endpoint:6002

NetOpt:

Annotation:MS Exchange Directory RFR Interface

IsListening:ACCESS_DENIED

StringBinding:ncacn_http:192.168.100.8[6002]

UUID:1544f5e0-613c-11d1-93df-00c04fd7bd09

ComTimeOutValue:RPC_C_BINDING_DEFAULT_TIMEOUT

VersMajor 1  VersMinor 0

rpcdump completed sucessfully after 1 seconds

0
 
btomkinsAuthor Commented:
Sembee,
Thanks for your quick reply

Sorry I disagree on the bit where you say its normal to get access denied.

From my reading its normal to get a 403.2 error not a 402.3 error.

I get the certificate ok. I are useing self certificates although I dont believe that that is the problem.

Using outlook on the LAN with HTTPS on the domain is the same story it just keeps asking for a password.

Outlook work fine with standard TCPIP on the LAN.
owa also works fine from internal and external networks.



Thanks
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
redseatechnologiesCommented:
Second opinion,

401.3 is normal, all of my exchange servers report that (and they are all configured correctly for RPC/HTTPS)

When you say "I get the certificate ok" does that mean it comes up and you say "yes" to it?

If so, that is a problem right there

-red
0
 
redseatechnologiesCommented:
Sembee,

Can you prune that log a bit please?  This thread hurts and it only has 4 posts! :)

-red
0
 
btomkinsAuthor Commented:
red,

Sorry about the rpcdump - How do you prune a comment?

Dont the "IsListening:ACCESS_DENIED" lines mean something.

> When you say "I get the certificate ok" does that mean it comes up and you say "yes" to it?

When I first connect on a machine it Actually does come up and say it is not from company that I have chosen to trust.
After I install the certificate the warning no longer comes up when I conect.

I'm sorry if I have not been clear.

The problem is still that the username and password dialog keeps coming back! ie Authentication is failing
I only get the 401.3 error after I click cancel.

Thanks
Brian
0
 
SembeeCommented:
You can't prune posts, but I can (as page editor) so that is what I have done.
The magic rule with log posts is to ask yourself would you read it? If not, then don't post it. If you report that you have the log, if there is likely to be anything of interest in there then an expert will ask you about it.

The first thing I always recommend with this feature is to use a commercial certificate rather than a home grown certificate. I tried to use a home grown certificate when I first started out with this feature and got failures. Switched to a home grown certificate and had it working in less than 20 minutes. For the US$20 (GoDaddy) or US$70 (RapidSSL) it costs for the certificate it well worth the investment compared to my time and it looks better from a deployment point of view.

401.3 is the same failure I get on my Exchange servers as well, and I am using RPC over HTTPS as I write.
It should prompt three times then fail.

Ensure that you have integrated and basic authentication enabled on the /rpc virtual directory in IIS Manager. Anonymous should not be enabled.

Simon.
0
 
btomkinsAuthor Commented:
Thanks Simon,
I added the integrated authentication and now outlook https connections work on the LAN using the  external domain the exchange proxy settings.

I dont know why but it just wont work on my machine externally.
I am buying a certificate to see if thats it.

thanks again
Brian
0
 
btomkinsAuthor Commented:

Well buying a certificate has made it work from the outside.
Thanks for your help.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

  • 5
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now