web app service accounts



I am looking for some feedback on an approach and if anybody has some
documentation to point me to that would be great....So here is the
scenario:

I have 2 .net apps on running on the same web server. Both apps have
databases on the same database server. (web and database are 2 separate
boxes)

Webapp1 has confidential data while Webbapp2 does not.

My question is should both of these apps run under the same app pool
with the same identity. My concern is that if the asp.net process on
Webapp2 was comprised then that same service account has read/write
access to the database of my confidential Webapp1.

I am a noobie, so any advice is greatly appreciated.

thanks

.



Relevant Pages

  • Re: Simples Rules make creating Big Balls of Mud impossible.
    ... excellent bracing internal test framework. ... other almost entirely thru the database. ... villages (apps). ... the internals of an object may leverage the stuff in other layers ...
    (comp.object)
  • Re: Simples Rules make creating Big Balls of Mud impossible.
    ... Why do Client Service architectures work so well? ... It's an internally self-consistent/closed system approach. ... other almost entirely thru the database. ... villages (apps). ...
    (comp.object)
  • Re: Newbie needs to see a large project
    ... >> I have been checking Python recently and have presented what little I ... > looking at building database-backed transactional web apps. ... and haven't built sophisticated database apps. ... maintenance/bug-fixing costs, transfer-of-ownership costs, etc.). ...
    (comp.lang.python)
  • Re: Newbie needs to see a large project
    ... >> I have been checking Python recently and have presented what little I ... > looking at building database-backed transactional web apps. ... and haven't built sophisticated database apps. ... maintenance/bug-fixing costs, transfer-of-ownership costs, etc.). ...
    (comp.lang.python)
  • Re: APIs - Sorry to ask
    ... > VB, Java etc. ... > language called Clarion to develop DB apps. ... > impossible to find good developers that can code in Clarion (Clarion is ... what database and database technology you use. ...
    (comp.databases)