As we know that IIS provides 5 kind of authentications
viz. Basic , Certificate , Integrated , Digest and

We have a .net application which will bw acceseed by
1) Netscape Browser on Linux Machine.
2) IE 5.5+ from MAC 9.0 and 10.0 OS .

4. Integrated Authentication Fails, Basic Authentication works

I was wondering if anyone has seen this before?  We have a Win 2k
server (sp3) w/ IIS v5.  The server is on an Active Directory with
valid domain accounts.  When we set the directory security to
Integrated we cannot logon w/ domain users.  The NTFS security is wide
open on the directory and the users are administrators.  If we create
a local acount, we can logon no problem.  If we switch to Basic Auth
we can logon no problem w/ the domain accounts.

As soon as we enable windows auth, no go?  Not sure if there is a
policy setting, hack, patch or what for this?

Any help would be appreciated.

Is there a way to configure IIS 6 to first try Integrated Authentication via
Kerberos only and if that fails, to fall back to basic authentication?  I
have some applications that need Kerberos proxy and fail if NTLM is used.

Eric Chamberlain, CISSP

