Article ID: 840613 - Last Review: November 17, 2008 - Revision: 3.0 Kerberos authentication to remote Web servers fails for Web proxy clients
SYMPTOMSYou try to use the Microsoft Internet Security and Acceleration (ISA) Server 2004, 2006, Forefront Threat Management Gateway Medium Business Edition or Threat Management Gateway Windows Essential Business Server Web proxy client to connect to an external or an internal domain Web site that requires authentication. The authentication data must be passed to ISA Server, or Microsoft Forefront Threat Management Gateway, Medium Business Edition WEBS before the authentication data reaches its destination. The duplicate (pass-through) authentication process does not recognize the Kerberos version 5 protocol authentication data. You are prompted to re-enter your credentials. CAUSEThis behavior occurs because ISA Server 2004 Web proxy client or the Microsoft Forefront Threat Management Gateway, Medium Business Edition WEBS web proxy client does not support Massachusetts Institute of Technology (MIT) Kerberos version 5 protocol pass-through authentication. If you use your domain account credentials to connect to an external or an internal domain Web site that requires authentication, the Internet Explorer program on the Web proxy client may try to perform the authentication process by using the Kerberos protocol authentication data on the destination server. When this behavior occurs, the pass-through authentication process does not recognize the Kerberos protocol authentication data because ISA Server or the Microsoft Forefront Threat Management Gateway, Medium Business Edition WEBS web proxy sever has removed the Kerberos protocol header.
For example, the pass-through authentication process does not recognize the Kerberos protocol authentication data in the following scenarios:
STATUS
This behavior is by design. MORE INFORMATIONIf you use local credentials for an account that exists on the destination Web site server, the Internet Explorer program that is on the Web proxy client uses NTLM authentication. The authentication process succeeds. | Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
