Tag Archives: IIS

Enabling .Net 4.0 on Web server

Not being an active ‘web’ developer for some time I stumble across an issue to make a small .Net 4.0 web application to work on a new Windows 2008 R2 server. After copying the application files to the local server (inetpub) and even creating the application in IIS (with no warnings or indications of a problem) I tried to test the application from the local machine.

That’s when I got the ‘HTTP Error 404.2’ error with further details ‘The page you are requesting cannot be served because of the ISAPI and CGI Restriction list settings on the Web server.’. As usual I did not read the whole page again and went on to find an answer on Google which did not really help too much – but it did point me in the right direction. Eventually I went back and read the full error/warning page that actually list the solution…

The solution is to enable .Net 4.0 for IIS (this is a 64-bit machine) doing the following:

  1. Open the IIS Manager and navigate to the server level.
  2. In the Features view, double-click ISAPI and CGI Restrictions to verify that the Web service extension is set to Allowed.

At least next time I will know better (or find it quicker) 😉

Force IIS to use NTLM

Today I’ve learned something new/old again. I’ve been having problems with an application that is running on IIS (6) where it kept on giving the error “HTTP Error 401.1 – Unauthorized: Access” when you try to access it by the machine name e.g. http://machineName/AppName. If you use the IP address then it works fine e.g. http://ipadress/AppName.

The application must use Integrated security because it only allows certain people to access it or only some people have full read and write functionality. In the code I must identify which user is logged on so it also make use of impersonation. To make sure the application itself has access to some databases it runs under an application pool that is configured under a domain account.

After some searching I came across the following kb article:

http://support.microsoft.com/kb/871179

The second workaround turns out to solve the problem. It turns out IIS6 does not authenticate the user correctly if only Integrated security is selected (anonymous is turned of) plus the application runs under an application pool that is configured with a different account (other than local system or network).

Update: Just to simplify searching for a workaround here is a copy of the text of the KB:

Workaround

To work around this behavior if you have multiple application pools that run under different domain user accounts, you must force IIS to use NTLM as your authentication mechanism if you want to use Integrated Windows authentication only. To do this, follow these steps on the server that is running IIS:

  1. Start a command prompt.
  2. Locate and then change to the directory that contains the Adsutil.vbs file. By default, this directory is C:\Inetpub\Adminscripts.
  3. Type the following command, and then press ENTER:
    cscript adsutil.vbs set w3svc/NTAuthenticationProviders “NTLM”
  4. To verify that the NtAuthenticationProviders metabase property is set to NTLM, type the following command, and then press ENTER:
    cscript adsutil.vbs get w3svc/NTAuthenticationProviders

    The following text should be returned:

    NTAuthenticationProviders       : (STRING) "NTLM"

Of course, doing this you do at your own risk 🙂