Microsoft KB Archive/942637

= A user cannot access a Web site that is published in ISA Server 2006 by using Kerberos constrained delegation if the user is not in the same domain as the ISA Server computer =

Article ID: 942637

Article Last Modified on 10/22/2007

-

APPLIES TO


 * Microsoft Internet Security and Acceleration Server 2006 Enterprise Edition
 * Microsoft Internet Security and Acceleration Server 2006 Standard Edition

-



SYMPTOMS
Consider the following scenario:
 * You publish a Web site in Microsoft Internet Security and Acceleration (ISA) Server 2006.
 * In the Web publishing rule, you configure ISA Server to use Kerberos constrained delegation (KCD) to delegate user credentials to the Web site.
 * A user authenticates with ISA Server by specifying a user principal name (UPN) in the credential.
 * The user is not in the same domain as the ISA Server computer.

In this scenario, when the user tries to access the published Web site, the user receives the following error message:

The page cannot be displayed

Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202)

Note This problem does not occur if the user specifies a Security Account Manager (SAM)-compatible user name in the credential.



CAUSE
ISA Server does not correctly parse the domain name from the UPN credential. Instead, ISA Server uses its own domain name in the ticket-granting service (TGS) request to request a Kerberos ticket on behalf of the user. If the user belongs to a different domain, the Active Directory directory service does not know the service name. Therefore, the Active Directory directory service does not give ISA Server a ticket for authentication.



RESOLUTION
To resolve this problem, apply the hotfix rollup package that is described in the following article in the Microsoft Knowledge Base: For more information, click the following article number to view the article in the Microsoft Knowledge Base:

942639 Description of the ISA Server 2006 hotfix package: September 24, 2007



WORKAROUND
To work around this problem, a user can specify a SAM-compatible user name in the credential when the user authenticates with ISA Server. A SAM-compatible user name resembles the following:

\



STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the &quot;Applies to&quot; section.

Additional query words: TGS-REQ KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN KDC_ERR_C_PRINCIPAL_UNKNOWN

Keywords: kbexpertiseinter kbqfe KB942637

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.