Article ID: 917145 - Last Review: December 4, 2007 - Revision: 1.5 RPC clients cannot use Kerberos authentication to authenticate with a server that you publish behind ISA Server 2004, Enterprise EditionSYMPTOMSYou publish Microsoft Exchange MAPI or other remote procedure call (RPC) services by using a rule in Microsoft Internet Security and Acceleration (ISA) Server 2004, Enterprise Edition. However, an RPC client that uses Kerberos authentication in this situation cannot authenticate with the published server. If you perform a network trace, you determine that ISA Server closes the RPC connection immediately after it receives an RPC Alter Context packet. CAUSEThis problem occurs because RPC protocol validation in ISA Server 2004 Enterprise Edition does not correctly identify and handle the RPC Alter Context packet. Therefore, ISA Server closes the connection. RESOLUTIONTo resolve this problem, install the hotfix that is described in the following Microsoft Knowledge Base article: 917902
(http://support.microsoft.com/kb/917902/
)
Description of the ISA Server 2004 hotfix package: April 24, 2006
WORKAROUNDTo temporarily work around this problem, configure the messaging client to use Windows authentication (NTLM). To configure Microsoft Office Outlook 2003 to use Windows authentication, follow these steps:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATIONIn an environment where the client can communicate with the Kerberos Key Distribution Center (KDC) and where the client can access internal DNS servers, the client may use Kerberos authentication. This behavior may occur if the following conditions are true:
824684
(http://support.microsoft.com/kb/824684/
)
Description of the standard terminology that is used to describe Microsoft software updates | Article Translations
|
Back to the top
