Today I’ve learned something new/old again. I’ve been having problems with an application that is running on IIS (6) where it kept on giving the error “HTTP Error 401.1 – Unauthorized: Access” when you try to access it by the machine name e.g. http://machineName/AppName. If you use the IP address then it works fine e.g. http://ipadress/AppName.
The application must use Integrated security because it only allows certain people to access it or only some people have full read and write functionality. In the code I must identify which user is logged on so it also make use of impersonation. To make sure the application itself has access to some databases it runs under an application pool that is configured under a domain account.
After some searching I came across the following kb article:
http://support.microsoft.com/kb/871179
The second workaround turns out to solve the problem. It turns out IIS6 does not authenticate the user correctly if only Integrated security is selected (anonymous is turned of) plus the application runs under an application pool that is configured with a different account (other than local system or network).
Update: Just to simplify searching for a workaround here is a copy of the text of the KB:
Workaround
To work around this behavior if you have multiple application pools that run under different domain user accounts, you must force IIS to use NTLM as your authentication mechanism if you want to use Integrated Windows authentication only. To do this, follow these steps on the server that is running IIS:
- Start a command prompt.
- Locate and then change to the directory that contains the Adsutil.vbs file. By default, this directory is C:\Inetpub\Adminscripts.
- Type the following command, and then press ENTER:
cscript adsutil.vbs set w3svc/NTAuthenticationProviders “NTLM”- To verify that the NtAuthenticationProviders metabase property is set to NTLM, type the following command, and then press ENTER:
cscript adsutil.vbs get w3svc/NTAuthenticationProvidersThe following text should be returned:
NTAuthenticationProviders : (STRING) "NTLM"
Of course, doing this you do at your own risk 🙂
0 Comments.