Re: Web Services and Access Control

From: Dominick Baier [DevelopMentor] (dbaier_at_pleasepleasenospamdevelop.com)
Date: 05/05/05


Date: Thu, 05 May 2005 09:55:27 -0700

Hello Francesco,

what kind of users do you have? corporate / external - do the all have domain
accounts, by chance?

Or do you have a user database?

the story for remoting and web services is quite different. do you use both?

---------------------------------------
Dominick Baier - DevelopMentor
http://www.leastprivilege.com

> Yes, I was thinking about insiders too, however the concept is the
> same.
>
> We still haven't deployed anything, but I think we can safely suppose
> that our web services are hosted in IIS and that we have a component
> which manages authentication (I wouldn't use Windows accounts). Once a
> user is authenticated, I guess the problem is passing the info to the
> other components, which takes us back to passing a "security token"
> parameter to all methods. Or maybe a cookie. Am I missing something
> here?
>
> Thank you.
>



Relevant Pages

  • Re: Win2K3 domain account connecting to Win2K VPN server in an NT4
    ... - since the server is not in the AD domain, you can't add it to the AD ... NT4 accounts can still authenticate, ... I verified that my test accounts could connect to the VPN before migrating ... > The authentication server did not respond to authentication requests in a ... ...
    (microsoft.public.win2000.ras_routing)
  • Re: Removing SPA from POP3 service of Windows 2003 Server
    ... If you wish to change the authentication type from "Local Accounts" to ... right-click on the server and bring up the properties. ... I think what you need to do is configure your Outlook accounts, ...
    (microsoft.public.windows.server.security)
  • RE: Separating authentication and authorization for admins was: RE: AD across both DMZ & LAN
    ... Subject: Separating authentication and authorization for admins was: RE: ... administrators and/or admin actions on the ... > internet from their PC's. ... so that we only have one set of user accounts to ...
    (Security-Basics)
  • Re: Strange auth denial with IE Integrated Security and IIS; but not Firefox, Netscape
    ... You can't configure this in IIS MMC, ... > Can someone explain why "NTAuthenticationProviders" would be missing> from the Metabase? ... > I had a problem where users would not be able to authenticate even> though I turned on Windows Authentication and configured my ASP.Net> app to use impersonation. ... By default when a machine is added to the AD the machine's>>> LOCAL and NETWORK service accounts are registered with AD. ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS6, SQL authentication and logging, can it be done?
    ... It is easier in Apache due to the weaker model for user accounts ... authentication, and authorization (IOW you do not want to use Windows ...
    (microsoft.public.dotnet.framework.aspnet.security)

Quantcast