Old 12-05-2009, 02:05 PM   #1 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,696
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default Off Topic IIS SSO Problem

Hi,
and sorry that this is so way off topic.

The problem that we have with IIS and SSO is just for one application.
We use it on loads of system but i cant get it working on this..

Maybe some one can shine a light on it.

Right now all is working if i Use the Internal DNS name.
But as quick that i use the External DNS namn it fails.
Giving me a "Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'." error.

I have added the spn for the remote address (setspn -a http/external.dns.name Internaldns)
But that did not change anything.

I have got the feeling that it is when IIS translate the user info over to the SQL server it all goes crazy.

Dose anybody have a idea?

The real weird thing is if i first go to the internal address where it works.
Then i can use the external address form another computer (as long that the ticket from the first computer is alive)

A well hope that some one with some IIS skills can shine a light on this. :P

Cheers,
WebFooL
WebFooL is offline  
Old 12-05-2009, 02:42 PM   #2 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

Do you see any blocked activity on ports 88, 113 or 751? I'm thinking that there may be Kerberos authentication attempts from the outside that are being blocked. I may be way off base, but its worth checking.
__________________
This space reserved for profound thought.....which does happen on occasion."
mdh is offline  
Old 12-05-2009, 02:48 PM   #3 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,696
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

I have only portforwarded port 80 on the external dns name..
Will try adding 88 and see if i that works.

Thanks mdh,
Let you know if it works :P
WebFooL is offline  
Old 12-05-2009, 03:04 PM   #4 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,696
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

Ok Now i have confirmation,

It is when the IIS send over NTLM sessions to the SQL server.

Sadly opening the Kerberos ports did not help.
WebFooL is offline  
Old 12-05-2009, 03:27 PM   #5 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

Have you read these?

http://blogs.msdn.com/sql_protocols/...nnections.aspx

http://www.phishthis.com/2009/10/24/...hentication-2/

http://support.microsoft.com/kb/319723
__________________
This space reserved for profound thought.....which does happen on occasion."
mdh is offline  
Old 12-05-2009, 03:42 PM   #6 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,696
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

I found the http://support.microsoft.com/kb/319723 and have started working after those instructions.
But i will have to check with the devs of the application on how they normally do SSO with external DNS name.

I keep you posted..

And thanks so far.. .
WebFooL is offline  
Old 12-05-2009, 03:51 PM   #7 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

Based on what you told me, I found those with a Google search on the following criteria:

iis ntlm sql port

Sometimes I get a hit, and sometimes I get hit...
__________________
This space reserved for profound thought.....which does happen on occasion."
mdh is offline  
Old 12-05-2009, 11:40 PM   #8 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,561
dwasserman is on a distinguished road
Default

Do you have internal dns? try put an static entry whit the external name (fqdn) whit the internal ip
dwasserman is offline  
Old 12-06-2009, 03:49 AM   #9 (permalink)
Untangle Ninja

 
WebFooL's Avatar
 
Join Date: Jan 2009
Location: Sweden (Eskilstuna)
URLs submitted: 57
Posts: 3,696
WebFooL is on a distinguished road
Send a message via MSN to WebFooL
Default

dwasserman,
Thanks for the idea. after adding the setspn http/remote.dns.name serveraddress
But i also want my staff to be enable to login without having to connect the VPN.

(otherwise i can be happy with the internal dns name)
WebFooL is offline  
Old 12-06-2009, 05:10 PM   #10 (permalink)
Untangle Ninja
 
dwasserman's Avatar
 
Join Date: Jun 2008
Location: Argentina
URLs submitted: 57
Posts: 3,561
dwasserman is on a distinguished road
Default

add the host in the reverse zone also (ip to name resolver) or play in all workstation with host file (an old trick).
dwasserman is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:59 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0