Last post Oct 18, 2017 09:44 AM by Billy Liu
Oct 11, 2017 01:14 PM|banan|LINK
I'm using windows authentication IIS v8.5 Windows Server 2012 R2 ASP.NET 4.5
Providers 1. negotiate 2.NTLM
Extended Protection: off
Kernel Mode Enabled
My problem is the page shows repeated login screen and no matter username & password I enter it takes credentials of last logged in user, the login screen disappears when I click "Ok" many times or click "Cancel" many times, even if I tick remember my credentials
it doesn't save.
it only works when I add system users as administrators in the web server which doesn't make sense @
I'm using Bootstrap theme /Entity Framework/Oracle Database, although I don't think it's a browser issue it appears in IE and chrome as well.
Oct 11, 2017 03:14 PM|PatriceSc|LINK
Let's try to take a problem at a time.
Having to make them administrators make me think you have wrong permissions on server side files. The file authorization module check if the Windows user is allowed to access a file and if the current windows user is not allowed it will show the dialog so
that you can enter some other user credentials.
In short all Windows users who will access this web site should have a read permission on the site directories.
Oct 12, 2017 05:31 AM|banan|LINK
as a test I added the tag
<allow users="KAMC-DM\alfayezb2" />
<deny users="*" />
the user alfayezb2 was able to access the site (along with the repeated login screen)
the other users shows 401 unauthorized screen(along with the repeated login screen as well)
Moreover, IIS_IUSRS & DefaultAppPool have full control access on project files, so the problem is not about folder level authorization nor a source folder permission, it's already allowing users to open the site and add records as well the problem is with
Oct 12, 2017 05:39 AM|banan|LINK
I'm not sure exactly how windows authentication works however I think there's some type of caching that need to be configured, the system takes the last user no matter what I enter in the login screen.
Oct 12, 2017 06:09 AM|banan|LINK
I know this might sound funny but when I click "Cancel" I do it 5 times before the page loads, and 12 times when I click "Ok" !!
Oct 12, 2017 02:51 PM|Billy Liu|LINK
Have you try to restart the website in IIS?
The windows authentication occurs in the iis.
I think you could try to clear the cache of IIS.
Oct 12, 2017 03:02 PM|PatriceSc|LINK
So it still doesn"t work for this user ? It is just that other users are filtered out earlier.
Try to check the exact status in the IIS log and check
I suspect that for now you have a "401.3 Unauthorized due to ACL on resource" status code. If not hupefully knowing which 401.x code you have should allow to narrow down your issue.
Oct 16, 2017 01:40 PM|banan|LINK
I moved the application to a whole new server with the same repeated login screen.
Oct 18, 2017 09:44 AM|Billy Liu|LINK
Please try to refer to the link below: