02-27-2013 10:49 AM - edited 03-18-2019 12:41 AM
Hey all,
Ok, setup a new TMS v14.1.1 Windows 2008 server, joined it to the domain and setup AD accounts in TMS. I have my Windows 7 PC on the same domain. When I connect to TMS it prompts for a username & password still. What am I doing wrong? Also the CCC JAVA prompt pops up too.
Thank you,
Justin Ferello
Technical Support Specialist
KBZ, a Cisco Authorized Distributor
e/v: justin.ferello@kbz.com
Solved! Go to Solution.
02-27-2013 11:46 AM
Hi Justin.
In IE options, i think its under the content tab and if you click custom settings for intranet you should get a few options. If you scroll to the bottom its a setting for authentication and you can set up "automatic login using your current credentials". What is this setting set to?
Im not sure if FF support automatc login like this.
/Magnus
Sent from Cisco Technical Support iPhone App
02-27-2013 11:54 AM
In E, Integrated authentication must be enabled. What URL are you using? Hostname? FQDN? IP? Can you try from IE directly on the TMS server? For Inegrated Authentcation to work, other than the client needing to be on the same domain, IE needs to known that the URL you are trying to reach is in the LocalZone. Depending upon the settings of IE, the URL you are using may be tied to a different Zone (Internet Zone usually). First access the TMS directy on the TMS using http://localhost/TMS just to make sure that IIS is configured currectly to use Integrated Authentication, and move on from there.
-Zac Colton
02-27-2013 10:55 AM
Hi,
What web browser are you using?
Firefox has some setting under about:config which control this - network.automatic-ntlm-auth.trusted-uris is one of the key ones, searching for ntlm will show the others.
02-27-2013 10:58 AM
Guy,
I have tried the latest FF, Chrome & IE all with the same results. Also I tried it from another domain PC with a different domain account to verify.
Thank you,
Justin Ferello
Technical Support Specialist
KBZ, a Cisco Authorized Distributor
e/v: justin.ferello@kbz.com
02-27-2013 11:46 AM
Hi Justin.
In IE options, i think its under the content tab and if you click custom settings for intranet you should get a few options. If you scroll to the bottom its a setting for authentication and you can set up "automatic login using your current credentials". What is this setting set to?
Im not sure if FF support automatc login like this.
/Magnus
Sent from Cisco Technical Support iPhone App
02-27-2013 11:54 AM
In E, Integrated authentication must be enabled. What URL are you using? Hostname? FQDN? IP? Can you try from IE directly on the TMS server? For Inegrated Authentcation to work, other than the client needing to be on the same domain, IE needs to known that the URL you are trying to reach is in the LocalZone. Depending upon the settings of IE, the URL you are using may be tied to a different Zone (Internet Zone usually). First access the TMS directy on the TMS using http://localhost/TMS just to make sure that IIS is configured currectly to use Integrated Authentication, and move on from there.
-Zac Colton
02-27-2013 01:09 PM
Thanks guys!
Interesting note. Adding the site to my "Intranet" allow list worked for IE. Also just changing the "Automatic Login" settings in IE worked for IE, however I had to change it on the "Internet" zone. I wonder why IE detects my internal domain as internet instead of intranet?
Another interesting note, if I add the TMS address to the "intranet" site list, then Chrome will not work. Chrome automatically tries to login and says "unable to authenticate". Apparently Chrome can use NTLM via the IE settings, but it does not work. Also tried the "automatic login" setting and that produces the same error in Chrome.
I am going to do some FF testing now as I hate using IE. Would prefer to use Chrome, but want the auto NTLM login support.
Thank you,
Justin Ferello
Technical Support Specialist
KBZ, a Cisco Authorized Distributor
e/v: justin.ferello@kbz.com
02-27-2013 02:48 PM
Hi,
For FF you'll need to add the URL to that setting I mentioned before under about:config and I found out there is another setting - search for ntlm - that meant it'll work if you use non-fqdn addresses - I often don't put the .cisco.com bit in the address bar as the network adapter settings on my windows pc have this in the DNS suffix list already. Nice that I've learnt something here too :)
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide