Web forms authentication, should I use it?

From: Vlad (vladi_dPLACEATHEREdotLV)
Date: 03/15/05

  • Next message: dl: "path for DirectoryEntry"
    Date: Tue, 15 Mar 2005 08:27:54 +0200
    
    

    Hello, people!
    I’m presently trying to choose an appropriate user authentication
    solution for online banking system implemented in ASP.NET, and as far as
    I understood the best practice of what Mcrosoft has to offer (with the
    exception of Windows integrated) is WEB forms authentication. So my
    question would be:
    - Would using forms authentication really be appropriate for such
    security demanding software, considering that authentication cookie will
    still be saved on the client’s computer where it cannot be protected by
    SSL anymore. Or is it better to implement some tailor made
    authentication/authorization mechanism, based on authentication
    information storing into session state/viewstate? What would you suggest?

    Best regards,
    Vlad.

    vladi_dPLACEATHEREdotLV


  • Next message: dl: "path for DirectoryEntry"

    Relevant Pages

    • Re: Windows NT authentication through a firewall?
      ... >authentication through a firewall? ... >but in practice that doesn't seem to be enough. ... UDP 500. ...
      (comp.security.firewalls)
    • Re: Best practices
      ... > can I find somewhere any whitepaper about authentication and best practice ... > application logon? ...
      (microsoft.public.dotnet.security)
    • Re: Windows NT authentication through a firewall?
      ... On Wed, 17 Dec 2003 19:00:20 GMT, The Lurker spoketh ... >authentication through a firewall? ... >but in practice that doesn't seem to be enough. ...
      (comp.security.firewalls)
    • Best Practice for Windows Authentication?
      ... Authentication instead of SQL Server Authentication. ... Server (this works but is it the best practice?) ... say create a user on the domain and use that in IIS as the anonymous user ...
      (microsoft.public.sqlserver.security)
    • Re: Windows NT authentication through a firewall?
      ... authentication in what type of domain, supporting which client OS's. ... > but in practice that doesn't seem to be enough. ...
      (comp.security.firewalls)

  • Quantcast