Re: ASP security

From: Ken Schaefer (kenREMOVE_at_THISadOpenStatic.com)
Date: 05/27/05


Date: Fri, 27 May 2005 15:42:33 +1000

Just with scenario 2 below. How can a user in A log onto a computer in B
when the appropriate trust has not been configured? DomainB does not trust
DomainA (you say you have a one-way forest trust in the reverse direction
only), so DomainB would not accept the credentials of a user from DomainA

Now, you say "an error is raised" - what is the error?

Cheers
Ken

-- 
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com
"Reza" <Reza@discussions.microsoft.com> wrote in message 
news:C72EBF84-DC61-42E4-A13D-C20CCAD73130@microsoft.com...
: Hello
:
: First of all thank you very much Duane for your reply. I am going to fully
: explain my network here. I have two domains, domain A and B. They are in 
two
: different forests. There is an outgoing trust from A to B so A trusts B 
and
: can authenticate it's users but not vice versa. All domains are in win2003
: functional level. Clients are WinXP. My IIS is in a computer in A , in 
domain
: controller of A I have AzMan. My web application passes credentials of the
: connected user to AzMan to check his acceess. Now we have 2 different
: conditions:
:
: 1. If a user in A logs on to a computer in A his credentials will be 
passed
: from IIS to azman and is authenticated successfully. Note that I ALWAYS 
get
: user name password pop up window from IE. It does not matter I enter a 
user
: from A or B to this window. As long as I have logged on to the computer 
with
: a user from the same domain as computer is in, everything is fine.
:
: 2. If a user in A logs on to a computer in B or a user in B logs on to a
: computer in A when the pop up window of IE appears regardless of whether 
you
: enter user from A or B it will raise an error.
: I hope I have clarified it fully.
:
: Thanks.
: Reza.
:
:
:
:
: "Duane Laflotte" wrote:
:
: > Reza,
: >      So let me see if I understand you correctly:
: >     1.  You have two domains (A & B).  Are they NT Domains or 2K
: >     2.  You must have a trust between these domains because a user from
: > domain b can login to a computer from domain A.
: >     3.  When you, as a User in A, hit the web application, from a 
computer
: > in A, all works ok
: >     4.  When you, as a User in B, hit the web application, from a 
computer
: > in A, you get the NT Login box?  Is that what you mean by "It doesnt 
know my
: > identity".
: >
: > I would say this can be caused by a few things.  The first think I would
: > look at is the rights of the files/virtual directory to make sure that 
users
: > from Domain B have rights to view them.  I'm assuming this is an 
intranet
: > application that uses NTLM Auth?  Which flavor of IIS are you using?
: >
: > Hope I can help,
: >
: > -- 
: > Duane Laflotte
: > MCSE, MCSD, MCDBA, MCSA, MCT, MCP+I
: > dlaflotte@criticalsites.com
: > http://www.criticalsites.com/dlaflotte
: >
: >
: > "Reza" <Reza@discussions.microsoft.com> wrote in message
: > news:9485B195-77C8-4FC0-9FDD-F25D68076577@microsoft.com...
: > > Hi
: > >
: > >  I have two domains A and B. I logon to a computer which is in domain 
A as
: > a
: > > user in domain B. When I connect to a web application in domain A it 
does
: > not
: > > know my identity. If I logon to the same computer as a user in its 
native
: > > domain (domain A) everything is ok. Does somebody know in detail why 
this
: > > happens?
: > >
: > >  Thanks.
: > >  Reza.
: >
: >
: > 


Relevant Pages

  • Re: Disincentives to logging for commercial anonymity services
    ... > The main focus of discussion regarding the use of logs by services ... > Little has been written or discussed regarding disincentives. ... including whether a system of trust can be ... offshore schemes, to use, not its own investigators, but those of certain ...
    (alt.privacy)
  • Re: kitty.avast.com scanning my ports and internal process trying to access their ip
    ... doesn't really help to build trust does it... ... Do we know whether its outbound or inbound? ... I will post the relevant part of the logs. ...
    (comp.security.firewalls)
  • Re: admt and virtual pc
    ... I've configure one domain and one subdomain. ... I think I don't need relationship trust because they are in the same forest. ... And I haven't found any log but sql logs and the don't show any errors. ... ADMT but you don't actually say that and more importantly ...
    (microsoft.public.windows.server.active_directory)
  • Re: MSN Messenger
    ... >>> Ideally I am after some kinda freeware plug in that logs the chat ... >> enough to chat to strangers on the internet either. ... >> her after the event will just destroy what trust she has with you. ...
    (uk.rec.motorcycles)
  • Re: Format HD, reinstall XP Home - no floppy drive
    ... - Steve Wozniak ... you and Ms Malke or Mr Malke just go right up to people in the Mall if ... >> Never trust a computer you can't throw out the window. ...
    (microsoft.public.windowsxp.newusers)