HELP: MS PDF "Building Secure ASP.Net Applications" - Forms Auth. and Anonymous Access

From: Mike Kingscott (mike_at_kingscott.f9.co.uk)
Date: 07/01/03


Date: 1 Jul 2003 08:19:35 -0700


Hi there,

I've been doing some noddy Forms Authentication stuff, got lots of
good information from Google

Groups, 4 Guys From Rolla, etc but got info from the source, namely
Microsoft's PDF mentioned in

the subject (it's at
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/secnetlpMSDN.asp?frame=true
, watch for URL-wrap).

Anyhoo, in chapter 8 there's an article that takes you through setting
up Forms authentication (starts on page 164), which I have followed
step by step, and it doesn't work. Here's the thing: the article
explicitly mentions allowing Anonymous Access on the virtual
directory, and when I do that, the app just sends me back to the login
form every time. If I set the security to Integrated Windows
Authentication, it works fine.

Thing is, in the How To guides at the end of the document, they do
another run through of setting it up (starting on page 377), and
forget to mention to set anon access. Of course, I followed this and
surprise, it worked.

So, the question is, do I need anonymous access? Bear in mind that I'm
writing for apps that will be on the Internet, where I won't have
Integrated Windows Authentication set on the site (or maybe I will,
you tell me).

Help?

Kind regards,

Mike K.



Relevant Pages

  • Re: both Windows and Custom Authentication for Web Services
    ... I configure IIS to use both Anonymous access and Integrated Windows ... The only time it is true is when only Integrated Windows authentication is ... Is there a way I can support both Win auth and Custom auth on the same WS ...
    (microsoft.public.inetserver.iis.security)
  • RE: Save IE password thorugh group policy
    ... that web site, this remote cookie will pickup the password so that the users ... You can configure IIS to Anonymous access or Digest ... Configure Authentication in IIS ...
    (microsoft.public.windows.group_policy)
  • Re: User ASPNET in SQL Server 2000
    ... When you hit a web application that has anonymous access, ... While I love integrated security in SQL Server, it is often a pain in web ... maintenance of accounts with access. ... >>> authentication", and has the same users as in Win 2000 ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: My boss....
    ... Click the Edit button under Authentication and access control, ... properties, Web site tab, Advanced button) ... Exchange virtual directory, clear the anonymous access box, clear Integrated ...
    (microsoft.public.windows.server.dns)
  • Re: Implement AuthenticationButton for anonymous and integrated access
    ... You'll want to set your portal up for anonymous access. ... Windows Authentication is checked. ... they are part of the SharePoint domain. ... users will be prompted to log in to access these javascript files. ...
    (microsoft.public.sharepoint.portalserver.development)

Quantcast