Single Sign-on problems  
Author Message
edwinchan





PostPosted: Wed Jan 25 15:41:11 CST 2006 Top

IIS >> Single Sign-on problems What makes these links do what they do - and does anyone know how to fix it?

These are both on our intranet and to the same server:

1) http://webapps/intranet/admin
(The above link will not prompt for your credentials)

2)http://webapps/ca.kt.org/intranet/admin
(This link DOES prompt for your credentials)

Web Programming70  
 
 
Kristofer





PostPosted: Wed Jan 25 15:41:11 CST 2006 Top

IIS >> Single Sign-on problems Hello,

I assume that the / in between webapps and ca.kt.org was NOT a typo. In
this case, the ca.kt.org/intranet/admin can have different NTFS settings
compared to /intranet/admin if they are two different locations on the
hard drive. If a virtual folder is involved, you may have configured the
virtual folder to require authentication, and the client is not
automatically logged on.

If the / between webapps and ca.kt.org was supposed to be a dot, this
behavior can be explained by different zones in Internet Exlorer. webapps
is considered to be in the Intranet Zone by default, while
webapps.ca.kt.org may be considered to be in the Internet Zone. Internet
Explorer will not automatically log on a user if the site is in the
Internet Zone.

Also see:

"Internet Explorer May Prompt You for a Password"
http://support.microsoft.com/?id=258063


There may also be other situations when this happens, and to give a
complete answer we need more information about your configuration (which
will most likely mean that you will find the issue yourself).

You need to check NTFS settings (if they are two different physical
folders), virtual folder settings, and the zoneing issue in Internet
Explorer. I think that if you check this, and compare them, you will find
the problem.

--
Regards,
Kristofer Gafvert
http://www.gafvert.info/iis/ - IIS Related Info


jonefer wrote:

>What makes these links do what they do - and does anyone know how to fix
>it?
>
>These are both on our intranet and to the same server:
>
>1) http://webapps/intranet/admin
>(The above link will not prompt for your credentials)
>
>2)http://webapps/ca.kt.org/intranet/admin
>(This link DOES prompt for your credentials)
 
 
jonefer





PostPosted: Wed Jan 25 17:40:03 CST 2006 Top

IIS >> Single Sign-on problems That was VERY helpful.
the "/" in between webapps and ca.kt.org WAS a typo... so thank you for
putting the answer - if it wasn't....

We added ca.kt.org to our trusted sites and that took care of the problem.
If there is a better suggestion, please let me know.

Thanks again!

"Kristofer Gafvert" wrote:

> Hello,
>
> I assume that the / in between webapps and ca.kt.org was NOT a typo. In
> this case, the ca.kt.org/intranet/admin can have different NTFS settings
> compared to /intranet/admin if they are two different locations on the
> hard drive. If a virtual folder is involved, you may have configured the
> virtual folder to require authentication, and the client is not
> automatically logged on.
>
> If the / between webapps and ca.kt.org was supposed to be a dot, this
> behavior can be explained by different zones in Internet Exlorer. webapps
> is considered to be in the Intranet Zone by default, while
> webapps.ca.kt.org may be considered to be in the Internet Zone. Internet
> Explorer will not automatically log on a user if the site is in the
> Internet Zone.
>
> Also see:
>
> "Internet Explorer May Prompt You for a Password"
> http://support.microsoft.com/?id=258063
>
>
> There may also be other situations when this happens, and to give a
> complete answer we need more information about your configuration (which
> will most likely mean that you will find the issue yourself).
>
> You need to check NTFS settings (if they are two different physical
> folders), virtual folder settings, and the zoneing issue in Internet
> Explorer. I think that if you check this, and compare them, you will find
> the problem.
>
> --
> Regards,
> Kristofer Gafvert
> http://www.gafvert.info/iis/ - IIS Related Info
>
>
> jonefer wrote:
>
> >What makes these links do what they do - and does anyone know how to fix
> >it?
> >
> >These are both on our intranet and to the same server:
> >
> >1) http://webapps/intranet/admin
> >(The above link will not prompt for your credentials)
> >
> >2)http://webapps/ca.kt.org/intranet/admin
> >(This link DOES prompt for your credentials)
>
 
 
jonefer





PostPosted: Wed Jan 25 17:55:02 CST 2006 Top

IIS >> Single Sign-on problems Also - I remember a co-worker designing a regfix that we could implement from
a central location to add "trusted" sites to a new computer - Would you or
anyone know how to do that?

"Kristofer Gafvert" wrote:

> Hello,
>
> I assume that the / in between webapps and ca.kt.org was NOT a typo. In
> this case, the ca.kt.org/intranet/admin can have different NTFS settings
> compared to /intranet/admin if they are two different locations on the
> hard drive. If a virtual folder is involved, you may have configured the
> virtual folder to require authentication, and the client is not
> automatically logged on.
>
> If the / between webapps and ca.kt.org was supposed to be a dot, this
> behavior can be explained by different zones in Internet Exlorer. webapps
> is considered to be in the Intranet Zone by default, while
> webapps.ca.kt.org may be considered to be in the Internet Zone. Internet
> Explorer will not automatically log on a user if the site is in the
> Internet Zone.
>
> Also see:
>
> "Internet Explorer May Prompt You for a Password"
> http://support.microsoft.com/?id=258063
>
>
> There may also be other situations when this happens, and to give a
> complete answer we need more information about your configuration (which
> will most likely mean that you will find the issue yourself).
>
> You need to check NTFS settings (if they are two different physical
> folders), virtual folder settings, and the zoneing issue in Internet
> Explorer. I think that if you check this, and compare them, you will find
> the problem.
>
> --
> Regards,
> Kristofer Gafvert
> http://www.gafvert.info/iis/ - IIS Related Info
>
>
> jonefer wrote:
>
> >What makes these links do what they do - and does anyone know how to fix
> >it?
> >
> >These are both on our intranet and to the same server:
> >
> >1) http://webapps/intranet/admin
> >(The above link will not prompt for your credentials)
> >
> >2)http://webapps/ca.kt.org/intranet/admin
> >(This link DOES prompt for your credentials)
>
 
 
Kristofer





PostPosted: Thu Jan 26 01:26:03 CST 2006 Top

IIS >> Single Sign-on problems Adding the site to the trusted sites is what you should do.

I am afraid i don't have an answer to your other question however. The
people in the Internet Explorer newsgroup may know this (they should
atleast know which key it is). I think it is stored in:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\Domains

But i am not sure.

I think that you can also do this in a group policy.

--
Regards,
Kristofer Gafvert
http://www.gafvert.info/iis/ - IIS Related Info


jonefer wrote:

>Also - I remember a co-worker designing a regfix that we could implement
>from
>a central location to add "trusted" sites to a new computer - Would you or
>anyone know how to do that?
>
>"Kristofer Gafvert" wrote:
>
>>Hello,
>>
>>I assume that the / in between webapps and ca.kt.org was NOT a typo. In
>>this case, the ca.kt.org/intranet/admin can have different NTFS settings
>>compared to /intranet/admin if they are two different locations on the
>>hard drive. If a virtual folder is involved, you may have configured the
>>virtual folder to require authentication, and the client is not
>>automatically logged on.
>>
>>If the / between webapps and ca.kt.org was supposed to be a dot, this
>>behavior can be explained by different zones in Internet Exlorer. webapps
>>is considered to be in the Intranet Zone by default, while
>>webapps.ca.kt.org may be considered to be in the Internet Zone. Internet
>>Explorer will not automatically log on a user if the site is in the
>>Internet Zone.
>>
>>Also see:
>>
>>"Internet Explorer May Prompt You for a Password"
>>http://support.microsoft.com/?id=258063
>>
>>
>>There may also be other situations when this happens, and to give a
>>complete answer we need more information about your configuration (which
>>will most likely mean that you will find the issue yourself).
>>
>>You need to check NTFS settings (if they are two different physical
>>folders), virtual folder settings, and the zoneing issue in Internet
>>Explorer. I think that if you check this, and compare them, you will find
>>the problem.
>>
>>--
>>Regards,
>>Kristofer Gafvert
>>http://www.gafvert.info/iis/ - IIS Related Info
>>
>>
>>jonefer wrote:
>>
>>>What makes these links do what they do - and does anyone know how to fix
>>>it?
>>>
>>>These are both on our intranet and to the same server:
>>>
>>>1) http://webapps/intranet/admin
>>>(The above link will not prompt for your credentials)
>>>
>>>2)http://webapps/ca.kt.org/intranet/admin
>>>(This link DOES prompt for your credentials)
>>
 
 
David





PostPosted: Thu Jan 26 02:58:27 CST 2006 Top

IIS >> Single Sign-on problems FYI: What you are doing is NOT "Single Sign On" but rather "Auto-Login" by
the client.

I know that functionality-wise, they accomplish similar things (client only
signs on once and can access multiple sites/vdirs), but from security
perspective it is very different:
- Auto-Login is client-side trust issue
- Single Sign On is server-side trust issue

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

"jonefer" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Also - I remember a co-worker designing a regfix that we could implement
> from
> a central location to add "trusted" sites to a new computer - Would you or
> anyone know how to do that?
>
> "Kristofer Gafvert" wrote:
>
>> Hello,
>>
>> I assume that the / in between webapps and ca.kt.org was NOT a typo. In
>> this case, the ca.kt.org/intranet/admin can have different NTFS settings
>> compared to /intranet/admin if they are two different locations on the
>> hard drive. If a virtual folder is involved, you may have configured the
>> virtual folder to require authentication, and the client is not
>> automatically logged on.
>>
>> If the / between webapps and ca.kt.org was supposed to be a dot, this
>> behavior can be explained by different zones in Internet Exlorer. webapps
>> is considered to be in the Intranet Zone by default, while
>> webapps.ca.kt.org may be considered to be in the Internet Zone. Internet
>> Explorer will not automatically log on a user if the site is in the
>> Internet Zone.
>>
>> Also see:
>>
>> "Internet Explorer May Prompt You for a Password"
>> http://support.microsoft.com/?id=258063
>>
>>
>> There may also be other situations when this happens, and to give a
>> complete answer we need more information about your configuration (which
>> will most likely mean that you will find the issue yourself).
>>
>> You need to check NTFS settings (if they are two different physical
>> folders), virtual folder settings, and the zoneing issue in Internet
>> Explorer. I think that if you check this, and compare them, you will find
>> the problem.
>>
>> --
>> Regards,
>> Kristofer Gafvert
>> http://www.gafvert.info/iis/ - IIS Related Info
>>
>>
>> jonefer wrote:
>>
>> >What makes these links do what they do - and does anyone know how to fix
>> >it?
>> >
>> >These are both on our intranet and to the same server:
>> >
>> >1) http://webapps/intranet/admin
>> >(The above link will not prompt for your credentials)
>> >
>> >2)http://webapps/ca.kt.org/intranet/admin
>> >(This link DOES prompt for your credentials)
>>