Re: Automatically authenticating Users

From: Aamir Memon (amemon1@hotmail.com)
Date: 11/06/02


From: "Aamir Memon" <amemon1@hotmail.com>
Date: Tue, 5 Nov 2002 16:56:21 -0800


Thanks Ian.
Sounds like a perfect solution, will start implementing it
next week.

Thanks,
Aamir

>-----Original Message-----
>You need to enable Windows/Integrated authentication on
the website(s)
>concerned. You should also disable anonymous access and
basic
>authentication. Right click the web site/virtual
directory, look at the
>directory security tab and check/uncheck the appropriate
options.That way
>the clients will authenticate transparently using
Kerberos or NTLM.
>The IIS servers will need to be in the same domain as the
users or in a
>domain that trusts the domain with the user accounts.
>
>For ASP.NET apps you will also need to edit the
web.config file to enable
>Windows authentication for that app.
><system.web>
> <!-- mode=[Windows|Forms|Passport|None] -->
> <authentication mode="Windows" />
></system.web>
>This allows IIS to pass through the Windows/AD
credentials to the ASP.Net
>application.
>See:
>http://msdn.microsoft.com/library/default.asp?
url=/library/en-us/vsent7/html
>/vxconASPNETAuthentication.asp
>
>--
>Ian Hellen
>Principal Consultant, BCC Security Solutions
>
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>Use of included script samples are subject to the terms
specified at
>http://www.microsoft.com/info/cpyright.htm.
>Please do not send email directly to this email address,
This address is for
>newsgroup purposes only.
>
>
>"Aamir Memon" <amemon1@hotmail.com> wrote in message
>news:5baa01c28394$82fc81a0$3aef2ecf@TKMSFTNGXA09...
>> I am designing an browser-based Interanet application
for
>> a client. Its a secure application and few
people/groups
>> within the company will have access to it. However,
>> client doesn't want people to login to this application,
>> system should be able to automatically authenticate
users
>> since they are already logged on to the Windows 2000
>> active directory domain. Client is willing to create
>> Active directory groups for each role (managers, Full
>> Access Users, Limited Access Users, etc). What is my
best
>> option to achive this?
>>
>> Server: Windows 2000 Server with active directory.
>> Client: All clients are Windows 2000 Professional with
IE
>> 5.
>> Application: ASP.Net with VB.Net
>> Storage: Microsoft SQL Server 2000
>>
>>
>
>
>.
>



Relevant Pages

  • RE: How to start/stop windows service on a remote machine?
    ... impersonate the client user(authenticated via integrated windows ... authentication in IIS) and access some remote protected resource(windows ... the problem you meet is a typical windows ... want to continue access other remote machine, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SP1 und Netzwerkauthentifizierung 802.1x
    ... Es gab mal ein Problem wenn das Client Certificat ... 953650 You cannot connect to an 802.1X wired network after you upgrade to Windows XP Service Pack 3 ... 838502 802.1x client authentication fails when you connect to a Windows Server ... IAS Best Practices: ...
    (microsoft.public.de.windows.vista.installation)
  • RE: AD client for W98
    ... Windows 95/98-based and Windows NT 4.0-based clients lack many of the ... features of Windows 2000 Professional that are related to Active Directory. ... The Active Directory client extension is an upgrade or patch for Windows ... This also includes support for display specifiers that allow ...
    (microsoft.public.windows.server.sbs)
  • Re: Win98 and SBS2003
    ... Please also note that although you can use a Windows 98 clients in the ... 323466 Availability of the Directory Services Client Update for Windows 95 ... Microsoft Small Business Server Support ... features of Windows 2000 Professional that are related to Active Directory. ...
    (microsoft.public.windows.server.sbs)
  • RE: 802.1x, Computers, Wired Security
    ... client to use EAP-TLS. ... Authentication-Provider = Windows ... Wired 802.1X Authentication failed. ... Network Adapter: Broadcom NetXtreme Gigabit Ethernet - Packet Scheduler ...
    (microsoft.public.windows.server.active_directory)