IIS 6 Integrated Security....risks??



Hello from Spain,

I have a web server running under IIS 6 on Windows 2003 Standar Edition,
domain controller.
I have 2 "sites" (web pages really, not IIS 6 Web Sites) running on it on
the same port (80).
The first one is plain HTML site, and I have Anonymous access security
applied to it. Works fine.
The second is an ASP.NET application, and I have Integrated Windows Security
applied to it. I have defined a ApplicationPool to this asp.net application
to run under an especific domain user account. Works fine too. When a user
connects to this application, the web explorer ask for user credentials.

My dude is: Is secure enought this configuration to my asp.net application
??
The server is running on Internet and Intranet at the same time. Some users
connects locally (from the LAN) and others connects over Internet to the
asp.net application sending their credentials.
As far as I know the credentials are sent encrypted??, but the pages
themselves are not encrypted, to do this i nedd an SSL connection?

Thanks a lot.

--

----------------------------------------------------------------------------
---
Roberto López
----------------------------------------------------------------------------
---


.



Relevant Pages

  • Re: force xp domain member to drop from domain?
    ... Right...but in this case, I never get to the credentials box...I change it to "workgroup", type in a workgroup name, click "OK", and then I get the modal that says the DC could not be contacted, and the only option is to "cancel" back to the first window. ... I also tried it at home in a set of virtual machines (Windows Server 2003 domain controller, ... Selected the Workgroup radio button, keyed "WORKGROUP", clicked OK, clicked OK on the credentials box - this was successful; after the restart the computer was no longer a domain member. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD sites and services
    ... A search for "Active Directory Sites" yeilds the following: ... After an Unsuccessful Domain Controller Demotion" ... http://support.microsoft.com?kbid=220140 "FRS Replication Protocol and Topology ... Windows 2000 Domain Controllers" ...
    (microsoft.public.win2000.active_directory)
  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • RE: join server 2003
    ... Cannot Promote a Windows Server 2003 Domain Controller into a Windows 2000 ... Make a backup of the schema master. ...
    (microsoft.public.win2000.networking)