Re: AD Login failure when using ActiveDirectoryMembershipProvider



No - thats not how you would configure an IIS6 -

you would configure the app pool to run as a domain account and use no impersonation.


-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

I'm afraid I don't understand your comments.

You're right that the default process identity is the local machine
ASPNET account. However, as I stated, I changed the anonymous user to
a domain account and enabled impersonation, so the process credentials
are now my domain credentials.

Why is this not realistic? It's the same way I would configure the
Windows 2003 server (i.e. change the anonymous account to a domain
account and enable impersonation).



.



Relevant Pages

  • Re: "Edit Users..." Menu Item Disabled in Telephony Management Sna
    ... On the member server, make sure the domain account you are using to log on ... Running "tapicfg show" revealed that I had no Active Directory TAPI ...
    (microsoft.public.win32.programmer.tapi)
  • Re: Domain could not be contacted problem
    ... > can either make the process run under a domain account, ... > To impersonate a domain account, you generally do this by enabling ... > impersonating the authenticated user in IIS. ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: Domain could not be contacted problem
    ... > can either make the process run under a domain account, ... > To impersonate a domain account, you generally do this by enabling ... > impersonating the authenticated user in IIS. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Kerberos Problem with App Pool running as Domain Account
    ... account, perhaps IIS itself has to as well (instead of the IUSR_IISSERVER ... An error occurred during logon ... Caller User Name: IISSERVER$ ... had to change this to use a domain account because our DR server needed ...
    (microsoft.public.inetserver.iis.security)
  • Re: Cannot find a users email address in Exchange 5.5 SP4
    ... I just dug out an old Exchange 5.5 book that I never had the need to open ... >>Google posts suggested using a Custom Recipient to forward inbound domain ... >>until I first added a domain account for the user. ... > You do not need to setup a domain account to accomplish this. ...
    (microsoft.public.exchange.admin)