Ideas on deferring authentication?

rgutter_at_bctf.ca
Date: 06/21/05


Date: 21 Jun 2005 14:01:43 -0700

We currently have a public IIS6 server in our DMZ. It's been made a
domain member to allow Basic Authentication against our AD for a
number of confidential documents - all within a single web - on the
server. (We don't want to maintain a separate user database.)

I can make this marginally more secure by moving the confidential
documents to an internal host and using UNC Passthrough authentication,
but I'd rather find a way to turn the public web server into a
standalone server. Is it sensible to think of moving the confidential
documents to an internal web server and performing authentication
there? I'm now allowing http into my protected network of course...



Relevant Pages

  • Re: Thumbnail security problem?
    ... have written or maybe you don't understand the HTTP 1.0 Basic Authentication ... will receive a 401 response from the web server. ... Ok, now that you see the basics, the problem we are seeing is as follows: ...
    (microsoft.public.security)
  • IIS6 - Integrated Authentication Probs
    ... server to a UNC share on another server ... It seems that when I use "integrated authentication" that the credentials ... Hence - this is a general problem with the way the web server is using my ...
    (microsoft.public.inetserver.iis.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)
  • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
    ... SYSTEM account. ... In IIS I took the virtual server that I was testing, ... Authentication premise. ... From a website perspective, I ...
    (microsoft.public.inetserver.iis.security)
  • Need help configuring Wireless Connection profile
    ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
    (microsoft.public.windowsxp.general)