Tuesday, March 28, 2017

You receive error 401.1 when you browse a Web site that uses Integrated Authentication and is hosted on IIS 5.1 or a later version


While Setting Windows Authentication in IIS we need to make following changes:

Click on Authentication -> Windows Authentication -> Providers

Move NTLM to up and Negotiate to down





It will work with localhost and IP, but it will not work with host name / domain name so you need to make following changes.

While Setting domain name / host name in Host file in URL we need to make following changes:

There are two methods to work around this issue, use one of the following methods, as appropriate for your situation.

Method 1: Specify host names (Preferred method if NTLM authentication is desired)
To specify the host names that are mapped to the loopback address and can connect to Web sites on your computer, follow these steps:
1.    Set the DisableStrictNameChecking registry entry to 1. For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:

281308 Connecting to SMB share on a Windows 2000-based computer or a Windows Server 2003-based computer may not work with an alias name

2.    Click Start, click Run, type regedit, and then click OK.
3.    In Registry Editor, locate and then click the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
4.    Right-click MSV1_0, point to New, and then click Multi-String Value.
5.    Type BackConnectionHostNames, and then press ENTER.
6.    Right-click BackConnectionHostNames, and then click Modify.
7.    In the Value data box, type the host name or the host names for the sites that are on the local computer, and then click OK.
8.    Quit Registry Editor, and then restart the IISAdmin service.
Method 2: Disable the loopback check (less-recommended method)
The second method is to disable the loopback check by setting the DisableLoopbackCheck registry key.

To set the DisableLoopbackCheck registry key, follow these steps:
1.    Set the DisableStrictNameChecking registry entry to 1. For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:

281308 Connecting to SMB share on a Windows 2000-based computer or a Windows Server 2003-based computer may not work with an alias name

2.    Click Start, click Run, type regedit, and then click OK.
3.    In Registry Editor, locate and then click the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
4.    Right-click Lsa, point to New, and then click DWORD Value.
5.    Type DisableLoopbackCheck, and then press ENTER.
6.    Right-click DisableLoopbackCheck, and then click Modify.
7.    In the Value data box, type 1, and then click OK.
8.    Quit Registry Editor, and then restart your computer.

https://support.microsoft.com/en-us/help/896861/you-receive-error-401.1-when-you-browse-a-web-site-that-uses-integrated-authentication-and-is-hosted-on-iis-5.1-or-a-later-version

No comments:

Post a Comment

Coronavirus and Our Priorities – Amir Nasiruddin Sayani

First few cases of Coronavirus got reported in Wuhan, city of China in the month of December 2019. China started taking immediate actions ...