XCON: NTLM Authentication Does Not Work Between Exchange Server 5.5 Internet Mail Service and Windows 2000 SMTP Stack (295439)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Exchange 2000 Server
- Microsoft Exchange Server 5.5
This article was previously published under Q295439 SYMPTOMS
When you set up NTLM authentication between an Exchange Server 5.5 Internet Mail Service and a Windows 2000 virtual SMTP server, the SMTP communication between the servers may not work in both directions.
If you activate the SMTP Protocol log for Exchange Server 5.5, the log shows that the first authentication is successful, but after the "MAIL FROM" command, the communication stops. Five minutes later (300 seconds) a second attempt is made. This time authentication does not work.
CAUSE
This problem can occur because the NTLM extensions of the Exchange Server 5.5 Internet Mail Service and the Windows 2000 SMTP stack are not compatible. The Exchange Server 5.5 Internet Mail Service supports NTLM authentication and NTLM encryption, but the Windows 2000 SMTP stack supports NTLM authentication and not NTLM encryption. This is also true for NTLM communication between Exchange 2000 Server and the Exchange Server 5.5 Internet Mail Service because Exchange 2000 enhances the Windows 2000 SMTP stack.
WORKAROUND
To work around this problem, use basic or anonymous authentication instead of NTLM authentication. If encryption is required, use Secure Sockets Layer (SSL). You can also work around this problem by upgrading the Exchange Server 5.5 computer to Exchange 2000.
STATUSMicrosoft has confirmed that this is a problem in Microsoft Exchange 2000 Server.
Modification Type: | Minor | Last Reviewed: | 4/25/2005 |
---|
Keywords: | kbbug kbnofix KB295439 |
---|
|