IIS虚拟目录托管远程共享及Windows身份认证问题求助
Root Cause
When using pass-through authentication to access a remote file share from IIS, WEB1 needs to impersonate the authenticated client user to access the share on CONTENT1. Cross-machine impersonation requires Kerberos Constrained Delegation (KCD) to be configured—without this, the authentication chain breaks, resulting in a 401.3 error.
Step-by-Step Resolutions
1. Configure Kerberos Constrained Delegation for WEB1
- Open Active Directory Users and Computers on a domain controller.
- Locate WEB1's computer account, right-click it, and select Properties.
- Navigate to the Delegation tab:
- Select Trust this computer for delegation to specified services only.
- Choose Use any authentication protocol.
- Click Add > Users or Computers, search for CONTENT1, and select it.
- From the service list, pick the cifs service (SMB file share protocol) for both
CONTENT1andCONTENT1.domain. - Save changes by clicking OK.
2. Verify SMB SPNs for CONTENT1
CONTENT1 needs valid SPNs for Kerberos authentication to its file share:
- Run this command in an elevated command prompt on a domain controller:
setspn -L CONTENT1 - Confirm entries exist for:
cifs/CONTENT1 cifs/CONTENT1.domain - If missing, add them with:
setspn -A cifs/CONTENT1 CONTENT1 setspn -A cifs/CONTENT1.domain CONTENT1
3. Validate Virtual Directory Settings
- In IIS Manager, go to the Example virtual directory on WEB1:
- Open Authentication: Disable Anonymous Authentication and enable Windows Authentication.
- Open Basic Settings: Click Connect as, select Pass-through authentication, and ensure Use application pool identity is unchecked (pass-through relies on the client's identity).
4. Confirm Client User Permissions
Double-check the client user accessing the site has:
- Share permissions on
\\CONTENT1\Example(minimum Read access). - NTFS permissions on
CONTENT1:\Example(minimum Read & Execute, List Folder Contents, Read).
Final Checks
- Restart IIS on WEB1 to apply delegation changes:
iisreset - Clear the client's Kerberos ticket cache to force new ticket issuance:
klist purge - Retry access from CLIENT1 using
https://ConfigMgt.domain/Example.
内容的提问来源于stack exchange,提问作者moosearch
相关产品推荐
相关产品推荐

