You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IIS虚拟目录托管远程共享及Windows身份认证问题求助

Fixing 401.3 Error When Accessing Remote Share via IIS Virtual Directory (Pass-Through Auth)

Root Cause

When using pass-through authentication to access a remote file share from IIS, WEB1 needs to impersonate the authenticated client user to access the share on CONTENT1. Cross-machine impersonation requires Kerberos Constrained Delegation (KCD) to be configured—without this, the authentication chain breaks, resulting in a 401.3 error.

Step-by-Step Resolutions

1. Configure Kerberos Constrained Delegation for WEB1

  • Open Active Directory Users and Computers on a domain controller.
  • Locate WEB1's computer account, right-click it, and select Properties.
  • Navigate to the Delegation tab:
    • Select Trust this computer for delegation to specified services only.
    • Choose Use any authentication protocol.
    • Click Add > Users or Computers, search for CONTENT1, and select it.
    • From the service list, pick the cifs service (SMB file share protocol) for both CONTENT1 and CONTENT1.domain.
    • Save changes by clicking OK.

2. Verify SMB SPNs for CONTENT1

CONTENT1 needs valid SPNs for Kerberos authentication to its file share:

  • Run this command in an elevated command prompt on a domain controller:
    setspn -L CONTENT1
    
  • Confirm entries exist for:
    cifs/CONTENT1
    cifs/CONTENT1.domain
    
  • If missing, add them with:
    setspn -A cifs/CONTENT1 CONTENT1
    setspn -A cifs/CONTENT1.domain CONTENT1
    

3. Validate Virtual Directory Settings

  • In IIS Manager, go to the Example virtual directory on WEB1:
    • Open Authentication: Disable Anonymous Authentication and enable Windows Authentication.
    • Open Basic Settings: Click Connect as, select Pass-through authentication, and ensure Use application pool identity is unchecked (pass-through relies on the client's identity).

4. Confirm Client User Permissions

Double-check the client user accessing the site has:

  • Share permissions on \\CONTENT1\Example (minimum Read access).
  • NTFS permissions on CONTENT1:\Example (minimum Read & Execute, List Folder Contents, Read).

Final Checks

  • Restart IIS on WEB1 to apply delegation changes:
    iisreset
    
  • Clear the client's Kerberos ticket cache to force new ticket issuance:
    klist purge
    
  • Retry access from CLIENT1 using https://ConfigMgt.domain/Example.

内容的提问来源于stack exchange,提问作者moosearch

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 23:47:27