?
Solved

Kerberos / NTLM

Posted on 2016-07-26
3
Medium Priority
?
95 Views
Last Modified: 2016-08-05
Hello

I have a website that seems to configure to use Kerberos. I see this as negotiate is selected but I know that is not enough.

Regardless I would like to bypass Kerberos Auth ( to avoid any misconfigure SPN etc ) and connect with NTLM so that I can be sure that site is configured correctly.

I move the MTLM above the negotiate but I am still having the same error popping up credential window and after 3 attempts it gives no authorized access error that seems to me a Kerberos error behavior

I have been wondering if there is anything else I need to consider to bypass Kerberos and to force NTLM

and How do you figure out if a site is using Kerberos except checking for the Authentication setting to see negotiate is on top. I Know that you can use Wireshark etc but I need a simple way . I can check the security log and see Kerberos in security audit logs but there is more than one site on the server. So how would I know whether or not a particular site is using Kerberos but not NTLM ?

Thanks All

F.
0
Comment
Question by:toronto2456
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 28

Expert Comment

by:Dan McFadden
ID: 41735494
Switching to NTLM will most likely not solve your issue.  Its probably a site config problem.

First thing is to make sure that if Windows Authentication is enabled, that you disable Anonymous Authentication.  Anonymous will hit first if both are enabled.

I would read thru this blog post and verify your setup.

Link:  https://blogs.msdn.microsoft.com/chiranth/2014/04/17/setting-up-kerberos-authentication-for-a-website-in-iis/

Unless you are using custom DNS names, you should not have the fiddle with SPNs.

Dan
0
 

Author Comment

by:toronto2456
ID: 41738958
Thanks Dan,

Yes, I have checked those. I have also checked for duplicate SPN. The only thing seems to be missing SPN for File shares.

custom DNS names are being used so need fo SPNs. Our contents are located in UNC Share on aNAS ,WEBSITESCONTENT, which is DNS alias for CORPDATA.HERCULES.tor.on.

Do you know what SPN needs to be created in this case.  I have checked web but found many different answers.

I think the problem is the missing SPN for NAS shares as I have been having security policy errors

Thanks

F.
0
 
LVL 28

Accepted Solution

by:
Dan McFadden earned 2000 total points
ID: 41742637
Yeah, but you are accessing the content on the NAS via IIS, therefore the URL to use is the URL of hte IIS server, not the FQDN of the NAS device.

You can configure a website to source its content from the UNC Share.

Link:  https://msdn.microsoft.com/en-us/library/cc768023.aspx?f=255&MSPPError=-2147217396

Dan
0

Featured Post

Get proactive database performance tuning online

At Percona’s web store you can order full Percona Database Performance Audit in minutes. Find out the health of your database, and how to improve it. Pay online with a credit card. Improve your database performance now!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Logparser is the smartest tool I have ever used in parsing IIS log files and there are many interesting things I wanted to share with everyone one of the  real-world  scenario from my current project. Let's get started with  scenario - How do w…
Debug Tools to analyse IIS process: This article focus on taking memory dumps from IIS to determine which code is taking more time and to analyse which calls hangs/causes more CPU usage. To take dumps,download the following. Install1: To st…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses
Course of the Month13 days, 4 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question