Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > november 2006

Filter by week: 1 2 3 4 5

Multiple SSL sites served from a single content path
Posted by TH at 11/29/2006 6:39:45 AM
Hi there, I wonder if anyone could help me with this? I have several versions of essentially the same web site, each has its own common name domain name, mysite1.com etc., and each is required to run in SSL mode. I intend to set these up as separate IIS web sites on the same server, each...more >>


RPC over HTTPS for Exchange
Posted by xrbbaker at 11/28/2006 3:25:01 PM
Outlook 2003 on Win2003 x64 server Terminal Session With Microsoft paid support we proved that my machine can support Outlook RPCoHTTPS. He config'd his user acct & exchange settings and we ran fine. When I config my profile exactly (only diff is no cache) as settings on my XP Pro desktop...more >>

MS IIS Setting: HTTP Failed To Connect if Using Machine Name
Posted by Ahmad A. Rahman at 11/28/2006 12:00:00 AM
Dear Experts, Previously I'm working on Microsoft IIS 6 on Win XP Pro SP2 to host my web application and its for development and testing purpose. Normally I use the machine name instead of localhost. So, I always use something like, http://mymachine/MYAPP/application.dll. But a few weeks...more >>

IWA connect to fileserver
Posted by Storcki at 11/27/2006 2:06:58 AM
Hi! Please can someone help me. I=B4m going nuts with IWA, delegation and kerberos authentification... We would like to do the following: - We set up an IIS 6 - we added a website with IWA - in this website we created 4 virtual directories which point to a fileserver (the folders beneath the ...more >>

Diff behavior for "Integrated windows authentication" in IIS6 Vs I
Posted by David Zhu at 11/24/2006 7:57:02 AM
Hi, I'm quite confused by the behavior of IIS6's "Integrated windows authentication"! Because when I specify an admin account as the Identity of the application pool which my web application used. Then, even an anounymous user in the intranet would be able to access my application,...more >>

local user not able to use iis
Posted by vishal at 11/23/2006 10:48:02 PM
Hi all, I am having win-xp proff. installed. I am using visual studio 2005 for my work. When I log in with an administrator rights I am able to open & make a new website by selecting asp.net website, location: HTTP, http://localhost/websitename , language:visual basic. but when i log ...more >>

How to create a web application on SBS2003 server ?
Posted by Tony Girgenti at 11/20/2006 11:29:12 AM
Hello. I'm trying to do create a VB ASP.NET web application on a SBS2003 server with IIS6.0, .NET Framework 1.1.4322, ASP.NET 1.1.4322 using Visual Studio.NET 2003 on an XP Pro, SP2 machine. When i attempt this, i get this "Web Access Failed" message: The default web access mode for this pr...more >>

"Failed to access IIS metabase" after installing Windows XP Pro
Posted by Wayne Erfling at 11/18/2006 10:14:15 AM
When I installed Visual Studio 2005 on Windows 2000 Pro, my asp.net 2.0 = sites on http://localhost worked fine. Then I upgraded the OS to Windows XP Pro and now all the sites report = "Failed to access IIS metabase", all the time ("file" websites work = fine). I have already been working t...more >>



Wrong cert for ssl site shows up
Posted by CGTech at 11/17/2006 7:43:01 AM
Configuration as follows: Running ISA2004 as firewall/proxy/publishing server, one exchange server, one web server. Exchange server has OWA setup with SSL, therefore the ISA has a listener for port 443. I setup a second listener useing SSL port 444, with a secure web site rule pointing to...more >>

Constrained Delegation Problem: SQL partially delegated
Posted by JimLad at 11/17/2006 7:03:03 AM
Hi, I have set up delegation and IT WORKS to link through to a back end SQL server. However for security reasons I want to limit the services that can be delegated to to MSSQLSvc on the db server. An SPN has been set up for the SQL server account on port 1433. When I swap to constrained ...more >>

Non-default website is asking for username and password: why?
Posted by JimLad at 11/17/2006 4:09:01 AM
Hi, I have a website using IWA (no anonymous logins) and delegation. I have IWA enabled on IE6 and the site is in the Trusted Zone. The same setup on the default website goes straight in without asking for credentials as I would expect. Why is the non-default website asking for credentials ...more >>

Impersonation and Delegation with ASP ASP.NET 1.1 IIS6 SQLXML
Posted by JimLad at 11/17/2006 2:27:42 AM
Hi, I'm working on Server 2003 servers with XP client. I'm trying to set up a fairly typical scenario of client - webserver - db server with Impersonation and delegation. Using default website which hosts ASP, ASP.NET 1.1 and SQLXML Web Release 1 Virtual Directory. There is another website (s...more >>

Security Alert: The Name of the Security Certificate Is Invalid or Does Not Match the Name of the Site
Posted by Tas at 11/16/2006 3:01:39 PM
I just purchased and setup an SSL certificate for an MS OWA server. The certificate works great for me from multiple computers I have tested it on. I can go to the secure page with no errors or pop-ups at all. But, a client who is trying to access OWA gets this error: Security Alert: The Nam...more >>

IIS Configuration
Posted by Gladyston at 11/16/2006 9:45:02 AM
Hello! I have an windows 2003 Standart with all updates and this only run IIS. I have many sites in IIS, but in some, I need set IUSR permission as write. This way i was hacked. What i can do different? Thanks...more >>

Security
Posted by Mr.Wright at 11/16/2006 6:33:02 AM
I have a website which I am hosting on a win2K3 SP2 server. Let's say www.mypage.com I would like to make www.mypage.com/admin only accessible from within a certain IP range. Is this possible? Would this setting be made on the server or could it be done through our PIX?...more >>

Virtual Directory to a remote UNC not working properly
Posted by dhoops at 11/15/2006 2:03:01 PM
Setup: IIS 6.0, Windows 2003 sp1 server. Web server and UNC server are on the same domain. Using 'Integrated Windows and Digest Authentication on both the Intranet site and the virtual directory on the web server. Problem: When trying to access a file on the virtual directory from outside t...more >>

Logging of ciphers / ssl versions used by clients?
Posted by Chu at 11/15/2006 8:33:28 AM
Hello, We are wanting to remove SSLV2 and enforce "stronger" encryption ciphers in our IIS 5.x and 6.x installations. However, the business units are concerned that doing so may preclude some users from accessing our website. I know all current browsers support SSLV3 and strong ciphers, but...more >>

Impersonation and Delegation with ASP.NET 2.0 on 2 Servers
Posted by Patrick at 11/15/2006 12:00:00 AM
Hello I have the following scenario - SQL 2005 server (serversql) - Windows 2003 with IIS (serveriis) - Windows 2003 ADS (serverads) I want to connect to an intranet application using NTML with impersonation and delegation. so for this I made the following change in web.config <identity ...more >>

Force Relogin. IIS6, ASP.NET app, IE6+ browser
Posted by Otis at 11/14/2006 12:20:02 PM
I'm trying to determine if it is possible to programmatically force an already authenticated user (Using Integrated Windows Authentication) to login again for my web site. I want them to be able to "logoff" for security reasons and not have to close their browser. That way if someone sits at...more >>

credentials not going to IIS automatically
Posted by David Thielen at 11/14/2006 7:41:02 AM
Hi; I am having a problem where IIS wants me to log in where IIS is on a Win 2003 server on the same domain as I am on on my workstation. This is for an ASP.NET 2.0 app (that I am writing) set to use Windows authentication. When running from VS 2005 using the integrated webserver, the we...more >>

Access Denied connecting to remote share through IIS
Posted by Hrocks at 11/13/2006 8:47:01 AM
I am accessing a document through a front end web application. The access pulls the document from a file share on another server. I continue to get the IIS credentials prompt and process monitor shows this: Operation: Create File Result: Access Denied Path: \\server\ITContent\Active\06\59\6...more >>

Security while publishing an website in Frontpage
Posted by PaulH at 11/12/2006 8:59:01 AM
I have had a frustrating day setting up IIS 6 with Frontpage Server extensions on my hope PC which runs Win XP Pro. Now when I try and publish using Frontpage or Sharepoint services I cannot seem to publish due to not knowing what username/password I am supposed to use. So the question is e...more >>

aspnet_isapi.dll security limit access to all but 1 file
Posted by Scanner2001 at 11/10/2006 11:56:57 PM
I am trying to limit access to folders in the web per user. I have tried two different approaches, neither of which I can get to work correctly. I have a windows 2003 r2 server, asp.net 2.0, front page extensions installed. My setup looks like this: /webvirtualdirectory/users/tom/.. /webvirtu...more >>

Disable serverobject
Posted by HEGMS at 11/8/2006 8:19:01 AM
Hi, Some of my users are using this function : set fso=server.createobject("scripting.filesystemobject") but I've seen that it can read directly in any file, so I just want to disable the library scripting in IIS but I don't know how. Thx...more >>

NTLM Authentication on IIS 6.0
Posted by kaverorzi NO[at]SPAM gmail.com at 11/7/2006 2:45:54 PM
I have an Intranet site set up on IIS 6.0 and have an intermitten problem. A couple of areas on the Intranet are restricted. We have Windows Intergrated Authentication enabled on the couple of pages that require access. I have a security group set up with only the users who require access and th...more >>

inhability to display http://localhost
Posted by Alfred Moussali at 11/7/2006 12:40:02 PM
My IIS local install is unable to display the localhost .asp page I got this error on IE7: "HTTP 500.100 - Internal Server Error - ASP error Internet Information Services -------------------------------------------------------------------------------- Technical Information (for support p...more >>

How do I make a local machine client certificate available to all users?
Posted by Assimalyst at 11/7/2006 5:03:06 AM
Hi, Using Windows Server 2003, i have set up a standalone certificate using the certsrv tools. When a client machine registers you can use the advanced form to 'Store Certificate in Local Computer Certificate Store'. This all works as intended when the client machine registers, but when ...more >>

Remote Desktop for Administration and Integrated Windows Authentication bug?
Posted by JimLad at 11/7/2006 2:57:26 AM
Hi, I ran Remote Desktop for Administration for the first time yesterday with 'helpdesk' credentials. These are not the credentials that I am logged onto my workstation with. However now when I access a website on that server using IE6 with IWA enabled, I am getting authenticated as 'helpdesk...more >>

[IIS 5] Homemade cert and SSL
Posted by Jeff Johnson at 11/6/2006 10:52:30 AM
For testing purposes I need to install a certificate on a development box. I generated a certificate using instructions found at this site: http://www.aspnetpro.com/newsletterarticle/2006/10/asp200610mb_l/asp200610mb_l.asp but I changed the command line slightly because I'm not using localhos...more >>

Multiple website in single IP, host header and SSL problem
Posted by prof_martin at 11/3/2006 6:55:02 PM
Hi, I have websites hosted in one server, single IP address using host header in IIS 6.0 (windows 2003 standard ed.) For illustration, in IIS I created 4 websites for respective domain name indentified on host header: www.domain1.com domain1.com www.domain2.com domain2.com I install...more >>

Delegation: IIS Server setup in typical 3-tier scenario.
Posted by JimLad at 11/3/2006 4:23:48 AM
Hi, Sorry to be asking the same question that everybody probably asks... Setting up delegation is killing me... Typical IE6/IIS6/SQLServer2000 3-tier Integrated Windows Authentication problem - I've got the double hop problem when using Impersonation, so I'm trying to set up delegation. Getti...more >>

authentication on multiple websites
Posted by test at 11/3/2006 12:00:00 AM
Hi, I have IIS 6 installed on win3k server and hosted on it are few websites with .asp and some are sharepoint websites. My question is, is it possible that if a user access one of the website (web.domain.com) and prompted for a username and password and logged in successfully, when he g...more >>

The minimum right to be granted at user to manage IIS
Posted by Nospam at 11/2/2006 6:24:36 PM
Hello, I've a question about managing IIS in Windows 2003 server. I have create a user profile to let log on locally at the server with a very low rights. Actuallly the user belongs to Backup Operators group in order to fully manage the backup; I also have delegated him to manage some OU in Ac...more >>

configure host name? localhost to localhost/(dir)
Posted by Ryan at 11/2/2006 4:42:01 PM
About: I am a web DESIGNER currently building all my sites within IIS on XP PRO. My layout is as follows: > Default Web Site (root) >> Site 1 (directory) >> Site 2 (directory) >> Site 3 (directory), etc. The Issue: Only the server edition allows me to create addtional root web sites, wh...more >>

baffled - ability to create new file lost
Posted by s_m_b at 11/2/2006 2:48:49 PM
On our IIS 5 (w2k server etc) using perl 5, our bulletin board has suddenly stopped adding new files. After some testing, its fine updating existing ones, but seems unable to add new - writing them via code. Since I havne't changed anything in the code, is it possibly some obscure piece of sy...more >>

SubjectAltName
Posted by Ronald Nissley at 11/2/2006 9:01:03 AM
Hi all, Is it possible to generate a CSR with SubjectAltName for IIS 6? If so, how? Please don't tell me a wildcard cert is the only option. :-) TIA, Ron...more >>

IIS Always asking for credentials
Posted by Alfred Moussali at 11/1/2006 4:24:02 PM
A couple of my PC computers where recently automatically updated by Microsoft, and now when I try to save or retrieve a web page in either of my PCs', to or from my personal web server that happens to be IIS 5.1 through Front Page; IIS is asking me for User Id. and password. On top the "loc...more >>

ISAPI filter with Basic Authentication and Asp.net impersonation
Posted by midway76 NO[at]SPAM gmail.com at 11/1/2006 11:04:46 AM
Hello, Is it possible in the context of an ISAPI filter (with Basic Authentication) managing the authentication to use impersonation in a asp.net project? I'm new to ISAPI filter... Here's my problem. I'm working in a Sharepoint 2003 (WSS) context. Instead of using the Active Directory ...more >>


DevelopmentNow Blog