Normal setup for Web page, web service, firewall secured database?



I think this is a fairly normal situation; outside the firewall are
two servers, one containing the various web applications that in this
case are .net, another containing web services, some of which the
public can access, some of which are locked into web applications on
the other server. The only path from outside the firewall where these
two servers are to inside where the database is through the web
services.

Is there any reason why impersonating user X to consume web services
would cause any problem if the webservice in turn is impersonating
user Y in it's call through the fire wall to get or set data?

I don't see any need to use windows authentication on the external web
server, so I don't think there will be a credential hop problem. In
one of the web applications, the aspnetdb method is being used, but
that would not be an authentication issue. Instead we'd just pass the
aspnetdb userid along with the request to the webservice and use the
internal webservice impersonation to decide what that userid means.

Am I missing anything critical here?

TIA,

.



Relevant Pages

  • Re: Patch testing
    ... In my SMB arena we post into community newsgroups and ask others what their results have been and get a "community" ... > servers but not to recreate every type of server in the enterprise (dc, ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
    (Focus-Microsoft)
  • Re: Patch testing
    ... servers but not to recreate every type of server in the enterprise (dc, ... >firewall security suite that prevent Web applications attacks, ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
    (Focus-Microsoft)
  • Form Authentication Across Web Servers
    ... I have a two ASP.NET2.0 Web applications which are published/deployed ... on two different servers. ... Users of these website can switch between these website as per ... Form authentication is being used to authorize user. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Patch testing
    ... > servers but not to recreate every type of server in the enterprise (dc, ... get good backup software that can do a full ... firewall security suite that prevent Web applications attacks, ... Download a FREE whitepaper on Security Policy Automation for Web Applications. ...
    (Focus-Microsoft)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)