Troubleshooting: Web Service Error "Negotiate,NTLM" (WinSSO Hosting Realm)

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    A realm configured to connect to a Web Service realm fails. Debug logs show a request to https://localhost/secureauthxx/webservice/membershipws.svc with the exception: "The HTTP request is unauthorized with client authentication scheme 'Anonymous'. The authentication header received from the server was 'Negotiate,NTLM'."

     

    Cause

    The realm hosting the Web Service is configured for Windows SSO.

     

    Resolution:

    Consider hosting the Web Service on a realm that is not configured for Windows SSO. If that is not possible, do the following:

    1. Open IIS Manager.
    2. Navigate to the realm hosting the Web Service.
    3. Expand the realm and click the WebService subfolder.
    4. In Feature view, double-click Authentication.
    5. Enable Anonymous Authentication, as shown below.

    IIS Authentication feature for the WebService subfolder with Anonymous Authentication enabled.

    It is now possible to connect to the Web Service again. Consider opening the Admin Console, navigating to the Logs tab on the realms identified above, and turning off the extra logging until it is needed again.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.