EPiServer Authentication using Kerberos and Custom App Pool Identity
This article describes how to get Kerberos handshake to work when the website is running with a pre configured account. It will only happen if you are browsing to the "computer's name", otherwise NTLM is used, which is the most common scenario.
I recently had a hard time to get Windows authentication working properly.
I installed a standard EPiServer CMS SP3, with Authentication mode "windows", and configured the site to use integrated security against the Sql Server.
This was going to be the intranet site, or at least the test site for the intranet.
The window dialog appeared and despite supplying all kinds of usernames and passwords, the site refused to accept my credentials.
What has happened? This is usually working fine out of the box with a minimum of necessary brain activity.
It took half a day before I found the solution, and I hope that anyone that encounter the same problem, will find some help here.
The problem was that the site (Application pool) was running under a custom identity, and that browsing was against the computer name, which means that Kerberos authentication is being used.
Browsing with the IP or the DNS alias, was no problem at all, since NTLM handshake works fine. Single sign on without any hesitation.
Log on the webserver using a domain admin account.