all groups > iis security > march 2007 > threads for march 1 - 7, 2007
Filter by week: 1 2 3 4 5
Problems with IWA and zone security
Posted by acastleberry at 3/7/2007 5:58:57 AM
I have a front end server with Exchange 2003 and Windows SharePoint
Services 3.0 installed on it. WSS and Exchange both share the same
virtual directory in IIS. I am currently setting up the WSS as an
intranet portal for our corporate users and both Exchange and WSS use
SSL.
My problem lies... more >>
ISS 6.0 & Active Directory
Posted by Beau at 3/6/2007 9:36:01 PM
I'm wondering if IIS 6.0 stores the AD information? I'm using IIS 6.0 and
Win 2003 Active Directory in Native Mode.
We're currently working on a web application that references AD to get the
username associated with the login. The system does the lookup correctly
and gets the name from Ac... more >>
W3SVC and asp.net
Posted by fixitchris via WinServerKB.com at 3/6/2007 8:58:47 PM
I ran into some problems between my test and production web servers.
TEST SERVER:
2003 Server 32bit
Default IIS setup
Default SQL setup
SELFSSL test cert
..net 2 running 32BIT
PRODUCTION SERVER:
2003 Server 64bit
NTFS locked down to prohibit WEBUSERS (IUSR/IWAM)
IIS:
not on sys... more >>
Restrict files to server, or other solutions
Posted by Ricki_Ricardo at 3/5/2007 12:59:13 PM
Here's the issue, we have several hundred users who we share files with
through our IIS 6 server, using ColdFusion. We use a long numerical string
for the folders, but the end files are always the same. For example,
reports.pdf. The problem is, someone could try to guess another's file,
w... more >>
Securing Port 443 SSL
Posted by Russ at 3/2/2007 3:20:05 PM
Hello,
We recently got audited and were told that we need to do the
following:
Disable SSLv2. Only SSL3 and TLSv1 should be enabled.
Also, disable the ciphers EXP-RC4-MD5 and DES-CBC-MD5.
We're using IIS6.
Any help in how to do this would be greatly appreciated.
Thanks,
Russ... more >>
IIS 6.0 Url Authorization - specific URL, non AD authentication.
Posted by Noremac at 3/2/2007 3:06:05 PM
Hello,
I have been looking around the web, went through the step-by-step guides and
I wanted to know if I can do these following things and HOW:
1) I have found no where to protect http://localhost/WebApp/Browse.htm with
a different role than http://localhost/WebApp/Edit.htm. So my questio... more >>
Website access through a DOMAIN ONLY
Posted by RajivI at 3/2/2007 2:57:08 AM
I have a domain xyz.com and a member server running Windows 2000 Server. I
have created an application which I would like to host it on IIS. The first
level of security that I would like to implement is that, this website should
allow access to users only from xyz.com. Hence in the Directory S... more >>
newbie needs help
Posted by Bruce at 3/1/2007 4:10:45 PM
I have just purchased a falsh program that updates weather data ivery
2 seconds and shows temp, wind direction/speed etc with gauges. I
have set it up on my local server on XP Pro, iis v.5, Everything
works the way it is supposed to until I select to lock the program
which should save the conf... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
IIS and SSL flaw...
Posted by dba-tamuk at 3/1/2007 2:13:05 AM
We have a web-serve with IIS 6.0 on Server 2003.
SSL is enabled, and the appropriate folders are check-marked to require SSL
communication.
Our problem is this:
If SSL is enabled for the site (http://mysite/) under folders (/IT/) and
(/fred/) then SSL works for the designated folders.
The... more >>
|