Singe forms-based login for website and OWA

From: DanielPS (DanielPS_at_discussions.microsoft.com)
Date: 07/08/05

  • Next message: TagaR: "Securing IIS 6"
    Date: Fri, 8 Jul 2005 09:46:01 -0700
    
    

    Hello,

    I've got a Windows 2003 web server that is also running Exchange 2003. I
    currently have a site set up so that when a user connects to the site, they
    are directed to a page that allows anonymous access without SSL. They can
    then click a link that will redirect them to a subdirectory that requires
    128bit SSL and that they log in with their AD account. The OWA site that
    they can then access also requires 128bit SSL.
    I've got no problem using forms-based authentication with OWA, and I've
    found a decent asp .net script that lets you login to a website using a form,
    but neither seems to authenticate the other. So, if I want just a single
    sign-on for both aspects of the site, I have to use non-forms authentication,
    with the pop-up window that my boss says in a no-no. So, how can I add a
    single forms-based authentication that brings the user to the main page, and
    also passes that authentication along when they go to their OWA page. Again,
    all accounts are defined using AD.

    Thanks for any help,

    Daniel


  • Next message: TagaR: "Securing IIS 6"

    Relevant Pages

    • Re: SSL & Certificates or Windows Auth
      ... Are you talking about client and server certificates? ... Is using Integrated Windows Authentication with SSL as ... secure as SSL with certificates? ... :>Is you are using something like "Basic Authentication" to ...
      (microsoft.public.inetserver.iis.security)
    • Re: Logon failures filling the event log
      ... Exchange web interface and CompanyWeb all require SSL and 128 bits. ... It's probably a brute-force attack. ... The authentication as seen from the authentication service comes from ... server farm (Windows 2003 standard, IIS6) hosting SSL secured, NTLM ...
      (microsoft.public.windows.server.sbs)
    • Re: Logon failures filling the event log
      ... Exchange web interface and CompanyWeb all require SSL and 128 bits. ... It's probably a brute-force attack. ... The authentication as seen from the authentication service comes from ... server farm (Windows 2003 standard, IIS6) hosting SSL secured, NTLM ...
      (microsoft.public.windows.server.sbs)
    • Re: SSL & Certificates or Windows Auth
      ... Is you are using something like "Basic Authentication" to authenticated ... against the Windows User database, then it is strongly recommended that you ... as the username/password are essentially passed as clear-text. ... So SSL doesn't help you as much here. ...
      (microsoft.public.inetserver.iis.security)
    • Re: get e-mail from Exchange Server 2003
      ... using SSL by looking at any of your OWA requests (eg do you see the padlock ... therefore i use "BASIC" Authentication. ... "GET" request will save attachment. ...
      (microsoft.public.exchange2000.development)