Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > KB943280 vista authentication to FQDN intranet site

Reply
Thread Tools Display Modes

KB943280 vista authentication to FQDN intranet site

 
 
super1
Guest
Posts: n/a

 
      01-25-2008
I posted this in a sharepoint group and didn't get much. I haven't seen
this come up here yet. As you may know vista has a problem
where users are prompted for credentials when opening office documents on a
sharepoint site that uses a FQDN. A hotfix has been released.
http://support.microsoft.com/?id=943280

The problem I see with this hotfix is the end user must install it AND edit
the registry to list the URLs of the servers they want to pass their
credentials to. I don't understand why the hotfix can't use the list of
URLs already provided by the user to decide which sites to consider
trustworthy. You know, the list of "Trusted Sites" or perhaps "Intranet
Sites".

Am I understanding the requirements of this hotfix correctly?
Any suggestions?

 
Reply With Quote
 
 
 
 
Jian-Ping Zhu [MSFT]
Guest
Posts: n/a

 
      01-28-2008
Dear Customer,

Thank you for your post.

In Windows Vista, Internet Explorer uses the Web Client service when you
use Internet Explorer to access a WebDAV resource.

The Web Client Service uses Windows HTTP Services (WinHTTP) instead of
Windows Internet (WinInet) API to perform the network I/O to the remote
host. WinHTTP sends user credentials only in response to requests that
occur on a local intranet site. Please note, WinHTTP does not check the
security zone settings in Internet Explorer to determine whether a Web site
is in a zone that lets credentials be sent automatically. This is different
from Windows Internet (WinInet) API which will check the security zone
settings in Internet Explorer.

Therefore, the Intranet Sites and Trusted Sites configured in Internet
Explorer security zone will take no effect on WinHTTP.

The solution is to install the hotfix 943280 and add URL of the server that
hosts the Web share in 'AuthForwardServerList' Registry Key. After that, if
any clients try to access a URL that matched any of the expressions found
in the "AuthForwardServerList" value, credentials will be sent to
authenticate the user even if he doesn't have a proxy configured.

I hope this helps.

Sincerely,
Neo Zhu,
Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
================================================== ===
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
================================================== ===
This posting is provided "AS IS" with no warranties, and confers no rights.

 
Reply With Quote
 
super1
Guest
Posts: n/a

 
      01-28-2008
This hotfix isn't practical enough to consider using.


"Jian-Ping Zhu [MSFT]" <v-> wrote in message
news:...
> Dear Customer,
>
> Thank you for your post.
>
> In Windows Vista, Internet Explorer uses the Web Client service when you
> use Internet Explorer to access a WebDAV resource.
>
> The Web Client Service uses Windows HTTP Services (WinHTTP) instead of
> Windows Internet (WinInet) API to perform the network I/O to the remote
> host. WinHTTP sends user credentials only in response to requests that
> occur on a local intranet site. Please note, WinHTTP does not check the
> security zone settings in Internet Explorer to determine whether a Web
> site
> is in a zone that lets credentials be sent automatically. This is
> different
> from Windows Internet (WinInet) API which will check the security zone
> settings in Internet Explorer.
>
> Therefore, the Intranet Sites and Trusted Sites configured in Internet
> Explorer security zone will take no effect on WinHTTP.
>
> The solution is to install the hotfix 943280 and add URL of the server
> that
> hosts the Web share in 'AuthForwardServerList' Registry Key. After that,
> if
> any clients try to access a URL that matched any of the expressions found
> in the "AuthForwardServerList" value, credentials will be sent to
> authenticate the user even if he doesn't have a proxy configured.
>
> I hope this helps.
>
> Sincerely,
> Neo Zhu,
> Microsoft Online Support
> Microsoft Global Technical Support Center
>
> Get Secure! - www.microsoft.com/security
> ================================================== ===
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> ================================================== ===
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>


 
Reply With Quote
 
Jian-Ping Zhu [MSFT]
Guest
Posts: n/a

 
      01-29-2008
Hello Customer,

Thank you for your feedback.

The solution provided in KB943280 is based on WinHTTP's working mechanism.
As explained before, the main reason is that WinHTTP does not check the
security zone settings in Internet Explorer to determine whether a Web site
is in a zone that lets credentials be sent automatically.

If you don't think this hotfix is practical, you could submit your
suggestions here:
https://support.microsoft.com/common...14&showpage=1&
WS=Wish&url=http%3a%2f%2fwww.microsoft.com%2firela nd%2fcontact%2f

You are welcome to upload suggestions and feedbacks like the following via
the above website:

Enhancement or feature addition to existing Microsoft products
Reproducible problem or bug with current version that needs resolution
Cannot find documentation of feature within the help files
Difficulty using the product
All beta products
Product packaging complaints
Added accessibility feature for a Microsoft product

In fact, we are always striving to capture any feedback from our partners
and customers so as to ensure that we are continuously developing products
that meet our customer needs. Suggestions like yours are always appreciated
and taken seriously.

Thanks again for using our products.

Sincerely,
Neo Zhu,
Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
================================================== ===
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
================================================== ===
This posting is provided "AS IS" with no warranties, and confers no rights.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SSO on intranet and VPN Connection Max Windows Vista Networking 2 05-06-2008 05:42 PM
Vista won't work on corporate intranet, need XP Pamela G Windows Vista Performance 5 02-20-2008 08:11 PM
Intranet connection George Mogyoro Windows Vista Installation 0 01-16-2008 11:41 AM
Vista/IE7: Internet works, Intranet does not bruce Windows Vista General Discussion 5 10-02-2007 05:21 PM
how to share files in intranet Lamb Chop Windows Vista General Discussion 2 05-22-2007 03:47 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59