Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > may 2005 > threads for may 15 - 21, 2005

Filter by week: 1 2 3 4 5

Anonymous Login Failure
Posted by seeker5 at 5/20/2005 1:47:45 PM
I have two Windows Server 2003 machines running IIS. Both use anonymous login, both use the default anonymous user accounts, both are Domain Controllers. The problem is that one allows anonymous login without issue, while the other prompts for a user name and password. If you type in iusr_com...more >>


IIS 6.0 Lock down tool
Posted by mitch at 5/20/2005 12:58:14 PM
Hi, Is there a IIS 6.0 lock down tool for Windows 2003 Server? If there is, where would it be located. Thanks. Mitch...more >>

Custom Errors
Posted by Andy Smith at 5/20/2005 7:48:05 AM
Hi there, Is it possilbe to redirect error pages (401, 404, etc), to a custom page using ASP/VBScript. I'd rather not use the custom errors tab in IIS as we have more than one web site running on the IIS server. Thanks very much/......more >>

Problem in connecting to ISAPI at medium and High levels
Posted by Ganesha at 5/19/2005 4:06:29 PM
Hi, I want to run ISAPI application in medium(pooled) or High(Isolated) level of application protection in IIS 5.0. When i run it in low level it runs without any problem. But when i run it in medium or high level only alternate requests will be served properly. For every other alternate...more >>

Cookie problem with ShowModalDialog and window.open
Posted by Jay Sullivan at 5/19/2005 4:01:11 PM
Hi, I have discovered an odd problem when using window.open from an IE window which was opened with ShowModalDialog. You would expect the new window to inherit the cookies from the same IE session which created the modal window, but in some cases that doesn't happen. It may get the coooki...more >>

IIS and non starndard URL problem
Posted by kr at 5/19/2005 1:05:39 PM
Hi! I have found a problem with non standard url it`s: http://server/doc_name.asp?param=value <- it works fine but http://server/doc_namse.asp/param/value <- IIS looks for such a server/doc_namse.asp/param/value document and it doesn`t find it. How to make IIS to execute d...more >>

Integrated Windows Authentication on a member server
Posted by John at 5/19/2005 12:50:11 PM
I am getting ready to upgrade our domain from Windows 2000 to Windows 2003. I have a web server that is running Windows 2000 and is currently a DC which will not be upgraded. The Windows 2000 web server hosts our Intranet site and uses Integrated Windows Authentication to validate users. I p...more >>

Basic Authentication - Sometimes No Prompt
Posted by Smitty at 5/19/2005 11:55:05 AM
Why is prompting for ID/PW random? Server: Windows 2000, SP4, IIS 5.0, teamshare and SQL 2000. sub-site (Default web/cr) has Basic Authentication Checked, only. NTFS security for /cr folder allows Authenticated Users, Administrators, System and denys Anonymous Most of the time a user i...more >>



IIS 6 on Win2003 with SP1
Posted by Harrison Midkiff at 5/18/2005 5:11:19 PM
Hello: I am bringing a new IIS 6.0 server online with Windows 2003 and SP1. SP1 has the new Windows Firewall in it. After the server came online I tried to access one of its sites. I couldn't access the site and then noticed the Windows Firewall was turned on. After turning it off every...more >>

AD Custom App Pool identity, Custom IUSR identity, and a lot more.
Posted by pj_servadmin at 5/18/2005 3:12:10 PM
I am probably going to misquote the microsoft rep I talked to (it was months ago), but here it goes: "In (mass vhost/webhosting/isp) type scenarios you should segregate all web applications that need high security by configuring custom App Pool Identities for each. There is a 'return self' fu...more >>

IIS / OWA
Posted by Andy Smith at 5/18/2005 9:51:04 AM
Hi there, This is a carry on from my Sessions/Cookies post... This is the setup I have: IIS running on W2K3 - IISSERVER Exchange 2003 - MAILSERVER I have an internal web site running on the IIS server which requires users to authenticate with their AD username/password. On this websit...more >>

.cfg and .ini files cause 404
Posted by Phil at 5/18/2005 9:27:29 AM
how do you allow .cfg and .ini files in a web directory . .IIS 6 gives a 404 error . but you can change the extension and access them . .it is NOT a path problem . it appears as some sort of security measure. Can someone please tell me how to allow these so I can get things working like they d...more >>

Kerberos & NTLM on IIS 6
Posted by Ethem Azun at 5/18/2005 2:11:02 AM
Hi, I have an IIS 6 on Win2003 registered on a domain. I'm running the following applications on this machine, - an ASP.NET Web App - Reporting Services Interface - Reporting Services Server All of the applications above use Windows Integrated Security. The ASP.NET application work...more >>

How to serve a certain file format in IIS6/2003
Posted by My Last Sigh at 5/17/2005 12:09:20 PM
I am having problems serving a file through http called myFile.vb_ I want to launch the file, but make it unknown to the browser. But it has to be known as a vb script file, because it launch some local file access functionality. Weird, I know. Does anyone know how to teach IIS 6.0 to exe...more >>

Sessions/Cookies?
Posted by Andy Smith at 5/17/2005 10:13:12 AM
Hi there, I have an internal web site running in a Windows Server 2003 Active Directory domain. I've set it to NOT allow annonymous access so that users are requested for their username/password when they access it. I've also got a logoff button on the website which I want to do exactly th...more >>

restricted directory does not work
Posted by ren14 at 5/16/2005 3:50:04 PM
I'm having a problem with IIS 6.0. I'm trying to restrict certain directories on our web server to certain domain users and it's not working properly. I'm using Basic Auth with anonymous access disabled. For example: I have a directory called "admin" and I've set the NTFS permissions on...more >>

unable to authenticate to IIS 6
Posted by OM at 5/16/2005 1:39:06 PM
Hi, I just setup an IIS 6 server on one of the member server in my AD domain and created a virtual directory. I would like to be able to use webfolder and IE to access this virtual directory However, I can't seem to get the authentication working properly. The only way I can get access...more >>

401.1 then 401.5 then "Page cannot be found" sent to client
Posted by Kevin S at 5/16/2005 9:03:48 AM
I have an IIS 6.0 web server set up using Integrated auth. When clients who are part of the domain go to the site, SOME of them get this result: When they first hit the web page, they get a page cannot be found error and if they hit refresh, it works EVERY time. I have used AUTHDAIG to get...more >>

authentication schemes
Posted by Krian at 5/16/2005 7:05:32 AM
With "passport" enabled on the IIS server, is it possible to limit to a specific set of passport users only instead of the whole community? Is it possible with just ISAPI extensions? ...more >>


DevelopmentNow Blog