- Check Web Sites: Identifier in our case it is 421949310,
- Get settings for NTAutheticationProviders property:
- Change the property to Kerberous:
C:\Inetpub\AdminScripts>cscript adsutil.vbs get w3svc/421949310/root/NTAuthentiationProviders "Negotiate,NTLM"
Change the property to NTLM:
C:\Inetpub\AdminScripts>cscript adsutil.vbs get w3svc/421949310/root/NTAuthentiationProviders "NTLM"
You can check all properties for AD object by ENUM command, for example to see all objects and settings under the virtual server root:
C:\Inetpub\AdminScripts>cscript adsutil.vbs enum w3svc/421949310/root
Friday, March 23, 2007
Change between Kerberous an NTLM authentication
Thursday, September 21, 2006
Kerberos
- In Internet Explorer, click Internet Options on the Tools menu.
- Click the Advanced tab, click to select the Enable Integrated Windows Authentication uncheck box in the Security section, and then click OK.
It will force IE use NTLM protocol instead Kerberos in case if web site use "Integrated Windows Authentication"
references: http://support.microsoft.com/kb/299838/EN-US/
Enabling Kerberos Event Logging on a Specific Computer:
http://support.microsoft.com/kb/262177/EN-US/
Introduction to Kerberos:
http://web.mit.edu/kerberos/www/dialogue.html
http://www.faqs.org/faqs/kerberos-faq/general/index.html
How to set SPN:
From description of "List Web part for Microsoft Dynamics CRM"
If using a Network Service or a Local account for the SharePoint Products and Technologies application pool identity, there should only be SPNs for the host headers under the computer account. If using a domain user for the application pool identity, all of the SPNs should be under the domain user’s object.
Kerberos and application pools:
About local accounts and default services:
http://www.microsoft.com/technet/security/topics/serversecurity/tcg/tcgch07n.mspx