Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Re: WSUS Cannot Sync through Proxy - 407 NTLM Authentication Required

Reply
Thread Tools Display Modes

Re: WSUS Cannot Sync through Proxy - 407 NTLM Authentication Required

 
 
TaurArian [MS-MVP]
Guest
Posts: n/a

 
      01-13-2007
Did you post to the WSUS Newsgroup?
http://www.microsoft.com/technet/com...pdate_services



--

====================================
TaurArian [MS-MVP] 2005-2007 - Australia
====================================
How to make a good post: http://www.dts-l.org/goodpost.htm
Backup and data recovery: http://www.acronis.com/
Enhancing file system performance: http://www.diskeeper.com/defrag.asp


"Paul Sharp" <USENET AT (REMOVE TO REPLY) PSHARP DOT NET> wrote in message
news:45a7fb54$0$8713$...
| (WSUS - Windows Server Update Service / BITS - Background Intelligent
| Transfer Service)
|
| Please apply your collective brains to the following problem...
|
| I have installed WSUS into a Win2K SP4 environment. This is to replace a
| previous SUS installation. SUS worked without any issues. However, after
| installing WSUS (and BITS 2), WSUS cannot synchronise to the Microsoft
| update site through our proxy server.
|
| Having done some investigation, the proxy requires NTLM authentication. If I
| set the proxy to require either anonymous or basic authentication for test
| purposes then synchronisation works. However, our security policy requires
| NTLM.
|
| The credentials used for authentication are a domain user account,
| configured in the WSUS Admin Synchronisation page. However, synchronisation
| attempts fail with a '407 - Authentication Required' response from the
| Proxy.
|
| As stated, the previous SUS installation did not have this problem. Also, if
| I log on interactively to any domain host with this domain account and
| launch Internet Explorer, IE will successfully authenticate to the proxy via
| NTLM. The problem only seems to affect WSUS (or perhaps BITS?)
|
| Running a LAN trace, I can see that initially the WSUS server tries to
| CONNECT anonymously, resulting in an initial 407 response from the proxy,
| specifying NTLM as the accepted authentication method.
|
| WSUS then sends another CONNECT request with a Type 1 base64 encoded NTLM
| string in the HTTP header.
| Proxy sends another 407 response with a Type 2 NTLM challenge in the HTTP
| header
| WSUS then sends a Type 3 NTLM message back to the proxy
|
| So far the above is what I would expect, but finally the Proxy sends yet
| another 407 Authentication Message back, this time including the HTML error
| page that would be displayed in a web browser at this point.
|
| This whole communication takes place over HTTP 1.1. WSUS always uses
| persistent connections, but Proxy always sets the Connection: Close header
| in the HTTP response, so the TCP session is always torn down and
| re-initiated between each WSUS/Proxy HTTP exchange. I am not sure this is
| correct. I have read that the NTLM exchange needs to take place over a
| persistent connection over HTTTP 1.1 (or using keep alives over HTTP 1.0).
| But I do not believe that the Proxy is at fault because SUS and IE (and
| anything else, including our Anti Virus updater) authenticate without any
| issues.
|
| I've run out of ideas now as to what may be going on. I've even decoded the
| Base64 NTLM strings from the HTTP packets, and as best I can tell they have
| the correct Type 1, 2 & 3 flags set respectively and contain the correct
| domain, host and user information where required.
|
| The proxy in question is Clearswift Mimesweeper for Web.
|
| I have seen lots of people when trawling Google that are having 407
| authentication issues with WSUS and proxy servers, but have not found a
| definitive solution. I found an article on Microsoft's site that suggests
| that BITS 2 can have issues with NTLM authentication, but again I am not
| clear on what the solution is. I have tried using the Local Security Policy
| on both the WSUS and Proxy servers to disable the sending of LM messages
| during NTLM authentication, but this does not appear to make any
| differences.
|
| Can anybody suggest where I go next, or has anybody actually discovered the
| solution to this problem?
|
| Any help would be very much appreciated.
|
| TIA
|
| Paul
|
|


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
407 Proxy Authentication Required Bill Windows Vista General Discussion 0 05-02-2008 08:25 PM
NTLM authentication login failure cathy Windows Vista Networking 1 11-21-2007 03:19 AM
NTLM Windows Authentication + group account + poor bandwidth + nasty fw rules = disaster lbrtchx@gmail.com Windows Vista Networking 0 11-07-2007 02:54 AM
Vista Defender WSUS and Proxy Authentication ThatsIT.net.au Windows Vista General Discussion 1 04-06-2007 03:44 AM
Windows Update fault - NTLM authentication may stop unexpectedly in Windows 2000 Quatermass Windows Update 2 09-12-2005 02:46 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59