Re: IIS 6 Integrated Security....risks??
- From: "Ken Schaefer" <kenREMOVE@xxxxxxxxxxxxxxxxxxxx>
- Date: Fri, 30 Nov 2007 13:20:46 +1100
"Roberto López" <rlopez@xxxxxxxxxxxxxxxx> wrote in message news:O%23GrfGoMIHA.4480@xxxxxxxxxxxxxxxxxxxxxxx
"Ken Schaefer" <kenREMOVE@xxxxxxxxxxxxxxxxxxxx> escribió en el mensaje
news:OE0nqFjMIHA.4880@xxxxxxxxxxxxxxxxxxxxxxx
is
"Roberto López" <rlopez@xxxxxxxxxxxxxxxx> wrote in message
news:uqen02bMIHA.5160@xxxxxxxxxxxxxxxxxxxxxxx
> Hello,
> My first concern is to ensure that the domain server and all data on it
> sure.protect
Integrated Windows Authentication does not secure your server, or the data
on it.
> And the user names and passwords are secured.
Windows already stores usernames and passwords securely. You need tothese "in transit", and also to ensure that user's do not disclose them to
others
But, with Integrated Windows Autentication the user name and password, as
far as I know, are sent encrypted?
Hi,
With NTLM authentication, the password is hashed using the NTLM v2 mechanism.
With Kerberos Authentication, the client sends an authenticator and service ticket. The username is not encypted, but the password is never transmitted to the server in question (as the trusted third party - the KDC/Domain Controller - knows all the passwords).
Cheers
Ken
.
- Follow-Ups:
- Re: IIS 6 Integrated Security....risks??
- From: Roberto López
- Re: IIS 6 Integrated Security....risks??
- References:
- IIS 6 Integrated Security....risks??
- From: Roberto López
- Re: IIS 6 Integrated Security....risks??
- From: David Wang
- Re: IIS 6 Integrated Security....risks??
- From: Ken Schaefer
- Re: IIS 6 Integrated Security....risks??
- From: Roberto López
- IIS 6 Integrated Security....risks??
- Prev by Date: Re: IIS 6 Integrated Security....risks??
- Next by Date: Re: Requiring Logon
- Previous by thread: Re: IIS 6 Integrated Security....risks??
- Next by thread: Re: IIS 6 Integrated Security....risks??
- Index(es):
Relevant Pages
|