Solved

IIS 7.0  Error (401.5) page overrules the original page

Posted on 2011-03-17
8
1,623 Views
Last Modified: 2012-05-11
I have a classic ASP web site, running on IIS 7.0

When browsing the pages locally they show up correct, but from an an external IP/PC I get the "401 - Unauthorized: Access is denied due to invalid credentials."

According to the IIS log its a 401.5 error. (I get the 401.5 for the ASP page, while the images get a 304).

I have tried changing the credentials for both the application pool and the anonymous authentication, but its still the same error.

After a lot of trial-errors, it changed the custom errors (the Error Pages section). In here I changed it to show detailed errors for both external and internal browsers (before it was configured to show detailed error messages for internal browsers and custom errors for external) - and now I don't get the Authentication Error any more!

If I change the setting back to not showing detailed error messages, I get the Authentication error again!

What am I doing wrong? Or is it a bug in IIS?

Thanks.

/Jesper
0
Comment
Question by:jesperhp
  • 5
  • 3
8 Comments
 

Author Comment

by:jesperhp
ID: 35158081
I have added a small screen cast of the problem. jesperhp-430027.flv
0
 
LVL 27

Expert Comment

by:BigRat
ID: 35164937
HTTP/1.1 401 Unauthorized
Cache-Control: private
Content-Length: 2566
Content-Type: text/html; Charset=ISO-8859-1
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDQQSDBCRB=ECPHPIKBLMDPDCPEMHCJPAON; path=/
X-Powered-By: ASP.NET
Date: Fri, 18 Mar 2011 12:37:00 GMT

is what I get together with a login form. Since this is the top level page there must be something wrong with the access rights to it (home and index page). The error reporting sounds like that access to those pages is also restricted. I'd first investigate why the top level login form returns a 401 response.
0
 

Author Comment

by:jesperhp
ID: 35165667
Hi BigRat,

Thank you for the comment. I have tried to figure out what element it is, which premissions is not OK - but so far it looks like its the entire default.asp page. And even then I still get the entire page loaded - there isn't any objects missing on the page from what I can tell!

The only thing I might think of, is if there is a reference to an seperate file like an image or so, which does not have the right permissions - but I can't see which file or object it could be.

Do you by any chance have a trick to identify the failing object?

Regards
Jesper
0
 
LVL 27

Expert Comment

by:BigRat
ID: 35166336
Like I said I got a login page :-

<! This script is a part of InfoExpress Webmodul. Do not edit the script>
<! Copyright (c) InnDevelop Technologies. www.InnDevelop.com >

<!Version 2.7.1>



<meta http-equiv="Content-Language" content="da">
<link href="stylesheet.css" rel="stylesheet" type="text/css">






<html>
<head>


<title>InfoExpress Helpdesk</title>
</head>

<body onLoad="document.forms[0].userid.focus();" class="PageBody">
<table width="100%" border="0" cellpadding="0" cellspacing = "0" height="100%">
    <tr height="60px"><td><table align="left" width="100%" cellpadding="0" cellspacing="0" border = "0" class="style1">
    <tr>
        <td>
            
		<img src="./images/InfoExpressLogo.jpg" alt="">
		
        </td>
        <td>
            &nbsp;</td>
    </tr>
</table></td></tr>
    <tr height="30px"><td><table align="center" cellpadding="0" cellspacing="0" class="MenuStyle1" background="./images/MenuBackground_Blue.gif" width="100%">
    <tr height = "30px">
        <td>
        </td>
    </tr>
</table>
</td></tr>
    <tr><td valign=middle>
        <center>
        <small><font color="#FFFFFF"> &nbsp;&nbsp;Du er ikke registret som bruger.<BR> </FONT></small><BR>

          <table border="2" cellpadding="2" cellspacing="0" style="border-collapse: collapse" bordercolor="#111111" width="50%" id="AutoNumber1">
            <tr>
              <td width="100%" class="TabelHeader">
              <p align="center"><font class="TabelTextHeader">Angiv brugerID og kodeord</font></td>
            </tr>
            <tr>
              <td width="100%" bgcolor="#E0E0E0">

        <CENTER>

        <form method="POST" action="default.asp?id=">
        <p>&nbsp;</p>
        <table border="0" class="TabelRow">
        <tr>
          <td width="50%" ><font class="TabelText">BrugerID:</font></td>
          <td width="50%"><input type="text" name="userid" size="20"></td>
        </tr>
        <tr>
          <td width="50%"><font class="TabelText">Kodeord:</font></td>
          <td width="50%"><input type="password" name="password" size="20">
        </td>
        </tr>
        </table>
        <p><input type="submit" value="Login" name="Action"></p>

              </td>
            </tr>
          </table>

        

        </CENTER>
    </td></tr>
    <tr height = "10px" class="footertext" background= "./images/MenuBackground_Blue.gif"><td width = "100%">
    <font class="footertext">Powered by InnDevelop InfoExpress</font>

    </td></tr>
    </table>
</body>
</html>

Open in new window


which came with the 401 response. Is this the custom page for a 401 or is this the default page? For it is strange that a 401 should return a protected page.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 

Author Comment

by:jesperhp
ID: 35166806
This is the normal page (default.asp), which should be returned without any errors. It is not a custom 401 page.

The strange part is, that this page is expected to show under normal conditions, but according to both the IIS log and the server response I should get a 401 error message on the page and instead the get the correct page. If I enable custom error pages (instead of detailed error messages) it will show the default IIS 401 error page.

So basically the site is working if I disable the custom error page function and selects to show detailed errors! With this setting, I would expect IIS to show some kind of error on the default page as the header returns the 401, but there is no error shown and the default.asp renders as expected.

If possible I would like to get rid of the 401 error message in the log, even though the page is showing correctly, but I can't figure out what is causing the 401.5 error!
0
 
LVL 27

Accepted Solution

by:
BigRat earned 250 total points
ID: 35167332
As you can see by my pervious post, the 401 response does NOT contain a WWW-Authenticate header, so the contents get rendered normally.

The rest of the page comes in, nicely with 302 not modified responses, except for the request for favicon.ico, which is returned as NOT FOUND.

I think you must have a setting in IIS somewhere which demands authentication without saying in what form. This could happen in IIS 7.0 if you have edited the XML configuration file per hand. You might have to post that here if you can't find the source of the problem, but, unfortunately it is 18:15 on a Friday and the Rat has to go home for cheese!
0
 

Author Comment

by:jesperhp
ID: 35180239
Hi Bigrat,

Thanks again for your comments. I think I found the problem - at least when I disabled .net for the application pool, I was able to avoid the error, and now it looks like the error has gone.

0
 

Author Closing Comment

by:jesperhp
ID: 35180245
I had to dig around a bit for the final solution, but the comment definitly help to point to the direction of the solution.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Lync server 2013 or Skype for business Backup Service Error ID 4049 – After File Share Migration
If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now