IIS6.0 use anonymous and integrated security a the same time



Hi all

I set up a IIS 6.0 sever a while ago when we were young and innocent and decided to implement a few simple security baseline for the intranet web site :
Integrated security on all the web sites
"authenticated user" with read access only on the files
"dev_group user" with write acces on the files
and various subdir right depending on the need.

We were happy, it worked fine, and since it was a brand new IT dev team with shiny new toys, the dev did a great job and lots of application were born using .NET

it was so well made that all the applications use a web service to identify each user and give him the correct right in each application. this WS is based on the windows authentication.

now it works so well we need to have some site accessed from other country branches our company is part of.

The problem is we don't share an active directory or any NT domain relationship at all, so I need to activate the anonymous access on the web site and if I do that, I cannot use the windows authentication anymore...

so what can I do to
allow anonymous user in my network to access my website
continue using the IIS/NTFS authentication for my domain users OR still get the security information with the anonymous acces activated.

is it even possible?

(my only option right now is to setup up a new server with a copy of everything but with anonymous acces... I don't like it at all.)

.



Relevant Pages

  • RE: Windows authentication and Role security for VS2005 website
    ... Protecting the web site with IIS/file system security is great from a ... security perspective. ... > | Forms authentication works fine, but with windows authentication the web ...
    (microsoft.public.vsnet.general)
  • Re: windows authentication in a different domain
    ... > i want to use windows authentication for my web site for best security ... > but my users are in domainA and web servers are in domainB. ...
    (microsoft.public.dotnet.framework.aspnet)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • [NT] Microsoft JScript Remote Code Execution (MS06-023)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... There is a remote code execution vulnerability in JScript. ... Configure Internet Explorer to prompt before running Active Scripting ...
    (Securiteam)
  • [NT] Cumulative Security Update for Internet Explorer (MS05-052)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in the way Internet Explorer ...
    (Securiteam)