all groups > iis security > august 2006 >
You're in the

iis security

group:

IIS FTP server authentication via Kerberos


IIS FTP server authentication via Kerberos Pierre Bru
8/28/2006 5:56:39 PM
iis security:
hi,

my boss ask me if it is possible to authenticate on an IIS server using
Kerberos(?) instead of the usual username/password

I'm not sure I understand what he means... :/
could s/o help me ?

TIA,
Re: IIS FTP server authentication via Kerberos Peter Schmidt
8/28/2006 8:25:59 PM
Hi Pierre

I believe what you are asked is, if FTP authentication between client and
server, can use a more secure way of authentication like in Kerberous, maybe
even using Kerberous Auth.
No, that's not possible, the FTP protocol is unsecure and communicate
username/password in plain text between the server and the client.

You can solve this by installing a Secure FTP (SFTP) server, but the FTP
server in IIS is not able to run SFTP. If you want to go for SFTP, you have
several options:
1. wait for Longhorn Server, where IIS will have the SFTP functionality.
2. find a 3rd party product for your FTP server, which is able to run SFTP.

I hope this answered your question.

Regards
Peter Schmidt
www.iis-digest.com


[quoted text, click to view]

Re: IIS FTP server authentication via Kerberos Bernard Cheah [MVP]
8/29/2006 12:00:00 AM
FTPS and SFTP are two different beast all together...
FTPS works via SSL, while SFTP relies on secure shell technology.

IIS FTP in v7 will offers FTPS.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: IIS FTP server authentication via Kerberos Pierre Bru
8/29/2006 12:00:00 AM
[quoted text, click to view]

is FTPS the same as what unix people call kerberos ftp ? or maybe these
so called kerberos ftp are either FTPS or FTPS server which validate the
username/password against some kerberos server ?

TIA,
Re: IIS FTP server authentication via Kerberos Bernard Cheah [MVP]
8/29/2006 6:42:15 PM
I'm not sure. but I think that would be more towards FTP authentication,
rather than FTP+SSL implementation.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button