Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Securing through the IIS web server domain logon |
|---|---|
| Date: | Wed, 18 Aug 2004 18:12:27 -0400 |
Hello Jeff, The customer can have high security needs and they can restrict directory access but you don't need to use domain authentication. Also if your application is shared with multiple customers then each customer will need their own domain account. This leads into a Microsoft licensing issue. The more customers you have the more Microsoft licenses you need. If this is the approach you want to go with, the authenticated username is a server variable you can grab in your asp code. Alternatively you can write an ISAPI filter that intercepts all traffic to your web server and do your authorization/authentication in the filter. If authorization/authentication is OK then let the traffic pass. If not OK, stop the traffic. You don't need domain accounts for this. Good Luck, Stan Guzik -----Original Message----- From: Koniszewski, Jeffrey [mailto:JKoniszewski@Kronos.com] Sent: Tuesday, August 17, 2004 5:21 PM To: webappsec@securityfocus.com Subject: Securing through the IIS web server domain logon Our application provides security via an application logon and web application session. We layer lots of access control on top of the user session. The web server is set to serve up files via the iusr account, i.e. web server access is via anonymous logon. We have a customer with high security needs that wants to restrict directory access on the web server to domain authenticated users (remove iusr access). This, as I understand it, would require the web server to prompt for domain authentication. Then file access on the web server would be via the authenticated domain user's account. However, our application still needs to authenticate the user as well. Actually, all we probably need is the user name. We have never set up to work this way. Is there a way to get the user name from the IIS domain logon? Is it accessible via the HTTP session? Thanks.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | ArtistScope, Sajeeva S. Arangalla |
|---|---|
| Next by Date: | Re: Interesting article on how development and web centric architecture change peoples views of security, Saqib . N . Ali |
| Previous by Thread: | Re: Securing through the IIS web server domain logon, Matt Fisher |
| Next by Thread: | RE: Securing through the IIS web server domain logon, Michael Silk |
| Indexes: | [Date] [Thread] [Top] [All Lists] |