Security Roles if not a member redirect them?

From: Richard Pullen (richard.pullen@southend.nhs.uk)
Date: 10/25/02


From: "Richard Pullen" <richard.pullen@southend.nhs.uk>
Date: Fri, 25 Oct 2002 08:56:54 +0100


Hi.

I've been playing around with security and I have had some difficulties with
the web.config settings.

I have set the security up corectly, (remove anonymous from IIS, set the
authentification to windows and allow roles etc in the config) and if you
are a member of the role then you are given access to the relevant web page.
(It has to be seemless hence role and windows security)

If the user is not a memeber the login box appears, what i am trying to is
redirect them to an unauthorised web page message, but all i get is the
standard 401.2: message.

I have tried customising error message to redirect but does not work at all.

The only fix around I have managed so far is on the default page on load
event , to add the not(user.isinrole("xyz")) and redirect them, though not
elegant it solves an immediate issue.

But can someone tell me how to trap the 401.2 message?

Are there any really good articles that explain in depth the configuration
files?

Cheers



Relevant Pages

  • RE: Do ICMP re-directs actually work ?
    ... Do ICMP re-directs actually work? ... On a Security note: Keep in mind that ICMP redirects ... that a host will on blind faith accept an ICMP redirect. ... gateway1 looks for the next hop and find gateway2 ...
    (Pen-Test)
  • Re: doesnt redirect
    ... Look under the Security tab. ... One of them is called the Internet zone and probably the one you are using. ... or better explain what you mean by>> redirect ... I think there are 2 interstitchal pages after submitting those login credentials before you get to the mailbox web page. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: MSN redirect for valid URLs?
    ... The Parasite Fight http://www.aumha.org/a/quickfix.htm ... More security tips at http://www.aumha.org/a/parasite.htm ... > browser redirects me to the MSN redirect page offering the "Similar ... > applications that require internet are functioning properly. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: IIS6 HTTPS POST not being returned to .ASP file...
    ... What "IIS Security" was involved with this? ... Failure to Redirect POST is a ... This posting is provided "AS IS" with no warranties, ... the response to any file, the response is displayed as a string in the ...
    (microsoft.public.inetserver.iis.security)
  • Re: Folder Reidrection w/o giving users FC
    ... > The link that clues me in that the user needs to be owener is the ... > directory so we can redirect? ... The owner is NOT the key. ... > This security ID may not be assigned as the owner of this object. ...
    (microsoft.public.windows.server.active_directory)