RE: SQL Authentication

From: Kevin McDonnell [MSFT] (kevmc_at_online.microsoft.com)
Date: 03/10/04


Date: Wed, 10 Mar 2004 19:38:07 GMT

Most web applications that are expose to the internet are annonymous.

Is your question related to making Trusted Connections to SQL in the same
context as the IUSR_machine account, or impersonate the user hitting the
web site?

Windows Auth from a DMZ environment to a server in your Corp environment
would expose numerous ports to enable. One method that you can evaluate is
having a domain in the DMZ with a 1 way Trust to the DC in your corp
environment. Then secure the channel between the two DC's with IPSec. You
should evaluate this in a lab first to make sure it meets your requirements.

Other choices are using Standard SQL Authentication with SSL encryption.
This would only require 1433. You could also consider using application
roles as well.

Thanks,

Kevin McDonnell
Microsoft Corporation

This posting is provided AS IS with no warranties, and confers no rights.



Relevant Pages

  • Re: Is complete home security possible?
    ... >>needs access to the SQL ports then they have to VPN to them. ... use a VPN or a IP:IP rule, but to expose it to everyone is just plain ...
    (comp.security.firewalls)
  • MS SQL 2000 Developer Edition.
    ... I am looking to install MS SQL 2000 on my laptop. ... purpose of which is to develop GUI and Web applications. ... Am I right in thinking the developer edition of MSSQL2K is ...
    (microsoft.public.sqlserver.server)
  • Re: Inserting Records into SQL tables
    ... MVP - Technologies Virtual-PC ... > Enterprise Manager to create the view. ... > View in SQL and was able to add a record so I would think that the View ... >>> build some web applications. ...
    (microsoft.public.access.forms)
  • Inserting Records into SQL tables
    ... "brilliant" add was to push the tables out to SQL so that we can begin to ... build some web applications. ...
    (microsoft.public.access.forms)
  • Re: Online replacement for spreadsheet
    ... Can exchange be persuaded to expose the data via any interface? ... store in SQL or something? ...
    (uk.net.web.authoring)