Re: Impersonation Issue



Basic auth just isn't sexy enough though ;-)


"Joe Kaplan" <joseph.e.kaplan@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:Ouo%23MrsZHHA.4684@xxxxxxxxxxxxxxxxxxxxxxx
That's the way it works. The way you are supposed to do this is to use
Windows authentication in the first place and let it do this for you.
Basic auth with SSL is much more simple.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services
Programming"
http://www.directoryprogramming.net
--
"-Steve-" <nntp@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eHoAsqnZHHA.2320@xxxxxxxxxxxxxxxxxxxxxxx
I'm using asp.net 2.0 login control to authenticate my users against AD.
I'm storing their encrypted password in session state, which I then pass
to the LogonUser method and succesfully impersonate their account.

The problem I'm having is that I have to continually re-impersonate the
user on every postback. Is there a better solution?

Steve





.



Relevant Pages

  • Re: Client Certificate Authentication with ADAM
    ... can't do this with ADAM users. ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services ... the normal procedures to configure ADAM for LDAP over SSL? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Mixed Mode Authentication in .net 2.0
    ... Basic auth should be used with SSL. ... authentication should use SSL anyway, ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall.
    ... does anyone else agree with me that using HTTP BASIC AUTH ... Once you're doing BASIC over SSL, ... endpoints aren't secure, you can't *really* secure the path between them. ... the first guy to try anonymous FTP to the site because the FTP server doesn't ...
    (Full-Disclosure)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall.
    ... does anyone else agree with me that using HTTP BASIC AUTH ... SSL is not a fix for the problem, SSL is just a way of evading the ... attacker is in a prime position to extort companies being managed by ...
    (Full-Disclosure)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall.
    ... SSL is not a fix for the problem, SSL is just a way of evading the ... I can bypass SSL with a man in the middle ... Login to the console is also plain text and basic auth. ... attacker is in a prime position to extort companies being managed by ...
    (Full-Disclosure)