AD GetObject fails in ASP page when using smartcard logon

AD GetObject fails in ASP page when using smartcard logon

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
AD GetObject fails in ASP page when using smartcard logon Mike 06-14-2005
Posted by Mike on June 14, 2005, 1:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I am having problems accessing Active Directory from VBscript in an ASP web
application when it is configured for smartcards using Directory Service
certificate mapping. The system scenario is as follows.

Server 1 - W2K3 Server as Domain Controller with Active Directory
Server 2 - W2K3 Server running IIS 6.0 and Exchange 2K3 Server
Client 1 - W2K3 Server as client with CAC smartcard and IE 6


IIS is configured for Directory Service mapping, SSL, "Enable client
certificate mapping" and Accept Client certificate.

The client uses a CAC smartcard to logon and invokes a Web application on
Server 2 via IE 6.

Web app on Server 2 loads ASP page using VBScript to call
GetObject("LDAP://CN=client1,CN=Users,DC=SERVER1,DC=COM") on User object to
retrieve user attributes.

GetObject fails with Err.Number = -2147016672 (0x80072020 -
ERROR_DS_OPERATIONS_ERROR)

In IIS Mgr properties for web app Virtual Directory, select Security/Edit
and uncheck "Enable client certificate mapping".

Now the user is prompted for username and password and GetObject succeeds.

Does anybody have any ideas?

PS I am told that if IIS cert mapping is used instead of DS mapping, it
works OK.

Thanks,
MikeC



Similar ThreadsPosted
OCSP and smartcard logon October 21, 2005, 7:20 am
Can smartcard for logon be disabled? January 30, 2008, 1:06 pm
smartcard logon without active directory November 28, 2006, 9:12 am
0x80070569: Logon failure: the user has not been granted the requested logon type at this computer. December 22, 2005, 9:06 am
Logon failure: the user has not been granted the requested logon t October 3, 2006, 1:54 am
home page September 28, 2005, 9:01 am
IAS Redirection to a web page June 20, 2006, 12:11 am
HOME PAGE November 16, 2006, 5:33 pm
Re: Home page hijacking September 23, 2005, 7:43 pm
RE: Home page hijacking January 20, 2006, 7:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy