<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Active Directory Authentication Part II</title>
	<atom:link href="http://mike.brevoort.com/2008/09/27/active-directory-authentication-part-ii/feed/" rel="self" type="application/rss+xml" />
	<link>http://mike.brevoort.com/2008/09/27/active-directory-authentication-part-ii/</link>
	<description>life technology etc</description>
	<lastBuildDate>Mon, 12 Jul 2010 13:14:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mike</title>
		<link>http://mike.brevoort.com/2008/09/27/active-directory-authentication-part-ii/comment-page-1/#comment-185</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 05 Nov 2008 14:32:05 +0000</pubDate>
		<guid isPermaLink="false">http://mike.brevoort.com/?p=113#comment-185</guid>
		<description>Joao, 

yes this makes sense.  As you said there must be a trust set up between all of the domains of the users trying to authenticate.  I&#039;m not quite following the last thing you said though about authenticating to these LDAP servers using basic credentials and not knowing who the user is.  Are you still trying to get IWA to work while manually attempting to resolve who the user is to there other domains?  In that case, yes it makes sense why that doesn&#039;t work.

Thanks,
Mike</description>
		<content:encoded><![CDATA[<p>Joao, </p>
<p>yes this makes sense.  As you said there must be a trust set up between all of the domains of the users trying to authenticate.  I&#8217;m not quite following the last thing you said though about authenticating to these LDAP servers using basic credentials and not knowing who the user is.  Are you still trying to get IWA to work while manually attempting to resolve who the user is to there other domains?  In that case, yes it makes sense why that doesn&#8217;t work.</p>
<p>Thanks,<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joao Afonso</title>
		<link>http://mike.brevoort.com/2008/09/27/active-directory-authentication-part-ii/comment-page-1/#comment-184</link>
		<dc:creator>Joao Afonso</dc:creator>
		<pubDate>Tue, 04 Nov 2008 16:36:15 +0000</pubDate>
		<guid isPermaLink="false">http://mike.brevoort.com/?p=113#comment-184</guid>
		<description>Hi!

I really liked your article! I&#039;m implementing a very similar scenario for a web application that is accessed by users from different domains and DCs.

In the first part you mentioned the words &#039;auto-login&#039;, which caught my attention since that&#039;s the way we&#039;re trying to go.

Like in your case, we&#039;re using IIS with Integrated windows authentication to bypass the authentication phase of the login process.

The problem is, because the other domains are not trusted inside the webserver&#039;s AD, we can&#039;t validate the users trying to log-in. IIS simply denies access to them.

Even if we try to find the users credentials in the any of the available LDAP servers (using a fixed user/pwd for navigation) we still have the problem of not knowing who the user is.

Does this make any sense to you?...

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi!</p>
<p>I really liked your article! I&#8217;m implementing a very similar scenario for a web application that is accessed by users from different domains and DCs.</p>
<p>In the first part you mentioned the words &#8216;auto-login&#8217;, which caught my attention since that&#8217;s the way we&#8217;re trying to go.</p>
<p>Like in your case, we&#8217;re using IIS with Integrated windows authentication to bypass the authentication phase of the login process.</p>
<p>The problem is, because the other domains are not trusted inside the webserver&#8217;s AD, we can&#8217;t validate the users trying to log-in. IIS simply denies access to them.</p>
<p>Even if we try to find the users credentials in the any of the available LDAP servers (using a fixed user/pwd for navigation) we still have the problem of not knowing who the user is.</p>
<p>Does this make any sense to you?&#8230;</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Active Directory Authentication Part I</title>
		<link>http://mike.brevoort.com/2008/09/27/active-directory-authentication-part-ii/comment-page-1/#comment-163</link>
		<dc:creator>Active Directory Authentication Part I</dc:creator>
		<pubDate>Sat, 27 Sep 2008 06:20:32 +0000</pubDate>
		<guid isPermaLink="false">http://mike.brevoort.com/?p=113#comment-163</guid>
		<description>[...] FINALLY posted a follow-up to this here   Share and Enjoy: These icons link to social bookmarking sites where readers can share and [...]</description>
		<content:encoded><![CDATA[<p>[...] FINALLY posted a follow-up to this here   Share and Enjoy: These icons link to social bookmarking sites where readers can share and [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
