Author |
Topic |
|
LSuddeath
Starting Member
8 Posts |
Posted - 27 September 2005 : 16:13:00
|
Greetings!
I'm a network administrator tasked with attempting to upgrade our web server from Windows 2000 to Windows 2003. Therein lies the problem!
We have Snitz installed on our Web Server, running with Integrated Authentication. This allows our users to automatically access the forums without having to login again (it reads the Active Directory login from the computer they are logged in to.)
My understanding is that if we move to Windows 2003 on the Web Server, Integrated Authentication will no longer work.
Question:
1) Is that a fair statement? Is there a scenario (other than placing Active Directory on the Web Server), where the Web Server can be upgraded and maintain Integrated Authentication with Active Directory?
Thanks for any input, and note in your replies that I did not install, and do not maintain the application, I'm just the server guy. Please be gentle. |
Lee |
|
pdrg
Support Moderator
United Kingdom
2897 Posts |
Posted - 28 September 2005 : 07:51:31
|
I'm not sure you're going to have as ahrd a time as you imagine - if the users are logged onto their domain accounts, their browser will (if prompted by the server) pass their credentials...if I remember right?!
Must admit I haven't tried and tested it all with W2K3S, but you could try building a test environment (with virtual servers/virtual PC's) and checking and tweaking on that? If you have MSDN or a partnering agreement, you've already got everything you need to get going on that (or you may be able to get a 90-day timebombed copy of w2k3s/virtual server etc from ms.com)
Let us know how you get on, if you don't get a definitive answer here!
Thanks :) |
|
|
LSuddeath
Starting Member
8 Posts |
Posted - 28 September 2005 : 13:58:30
|
When we first started looking at this about a year ago, the developer who was working with Snitz told us that if we upgraded to Windows 2003 on the web server, then the integrated authentication would no longer work.
He said that he was told that since Active Directory does not reside on the web server, in Windows 2003 Snitz does NOT pass the credentials through from the browser. It had something to do with LDAP having to make a second jump to get to AD.
We're under time constraints (aren't we all?), so I don't know if I'm going to have time to fully test an upgrade. |
Lee |
|
|
pdrg
Support Moderator
United Kingdom
2897 Posts |
Posted - 29 September 2005 : 04:45:25
|
you should be able to build a virtual server test environment pretty quickly
Maybe one of the devs has more info for you? |
Edited by - pdrg on 30 September 2005 05:00:12 |
|
|
roryniland
Starting Member
8 Posts |
Posted - 03 November 2005 : 11:40:40
|
we have upgraded to win2K3 SP1 on all DC's and I'm running snitz on a Win2K3 server
Integrated authentication works if you use the fix here : http://forum.snitz.com/forum/topic.asp?TOPIC_ID=56753
NT groups have to be switched off also .. and the username is constantly ROOTDSe |
This account was hacked into by Image, a very honest guy as you all can see! Stealing people' s passwords IS his pasttime. |
|
|
Kal Corp
Average Member
USA
878 Posts |
Posted - 04 November 2005 : 09:19:19
|
Hail everyone. Its been along time since I been one the forums.
Looks like I was removed as the moderator :-(
We still have a mixed environment over here. But everything is still working ok. I just have one issue on the email info. They changed the exchange servers already now I got to get it from another ldap call
Going to work that soon.
|
|
|
pdrg
Support Moderator
United Kingdom
2897 Posts |
Posted - 04 November 2005 : 12:00:59
|
Kal, is your email address in your profile current? |
|
|
|
Topic |
|