Hello,
I have a internal website running on IIS 6.0/Windows 2003 SP1 set to
Integrated Authentication only. The server is a member of our Windows 2000
domain. All Windows 2000 domain-member machines can get to the site with no
problem. All Windows XP domain-member machines are prompted for their
user/pass/domain and it fails after 3 attempts even though you type in your
correct user/pass/domain. This problem goes away if you turn off the
"Enable Integrated Windows Authentication (requires restart)" Setting in IE6
on the XP machines. If you turn on this setting on 2000 machines it fails
as well. On an non domain member, it doesn't matter what this setting is.
It will prompt you for your user/pass/domain and let you in with a valid
account.
With the failures I see the following in the security event log of the
server. It shows that no username and domain was passed for kerberos
authentication. I do not want to turn this setting off on all my Windows XP
machines. Anyone know how I can fix this on the server side?
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 5/2/2006
Time: 1:35:26 PM
User: NT AUTHORITY\SYSTEM
Computer: SHRPDEV01
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain:
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name: -
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.10.1.33
Source Port: 1070
Steve March
>> Stay informed about: Enable Integrated Windows Authentication (requires restart..