Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > august 2007

Filter by week: 1 2 3 4 5

SSL, private key with a blank password
Posted by Edward Kniazycki at 8/30/2007 6:26:24 AM
Hello, Could you please help me solving the following problem: I've got both private key (.key) and SSL certificate (.cer) files, generated by the company hosting my domain. (I've ordered them through their website, so I didn't create a certificate request from IIS Manager.) Now I'm trying to i...more >>


WebDAV and folder permissions
Posted by cln at 8/28/2007 7:08:56 PM
Can I, as admin, give webDAV users permission to GIVE permissions to subfolders? I have teachers that want to administer student's folder. I need a lead or answer please. thanks, cln ...more >>

Client Certificate Auth only for certain urls handled by ISAPI fil
Posted by Kshitiz at 8/27/2007 11:18:02 PM
I have written a ISAPI filter. It handles all the request urls and generate output. None of the urls are mapped to file system. Now I want anonymous access to most of the urls served by this ISAPI filter. However for certain urls, I want to enable client certificate based authentication....more >>

Client Certificate and SSL termination
Posted by kjartan at 8/24/2007 8:04:04 AM
Hi all. We are currently building a web site that requires a client certificate for authentication (certificate hosted on smart card). We are having some problems implementing the "Sign out" functionality of the website. What we are trying to do is to implement the following scenario: 1....more >>

Getting error : Start attempt failed.
Posted by Kshitiz at 8/24/2007 12:40:02 AM
I enabled User Authorization and my IIS is not starting up: User Authorization file content : <?xml version="1.0" encoding="utf-8"?> <AzAdminManager MajorVersion="1" MinorVersion="0"> <AzApplication Guid="622bc2f4-6a22-4415-991b-d93a13764ba4" Name="IIS 6.0 URL Authorization" Description...more >>

how to secure an ftp site in iis
Posted by Mr Computer at 8/23/2007 7:46:01 PM
Could anyone help me to secure my ftp site in iis? I am not running a domain, but am using windows 2003 server. thanks...more >>

Access to network drives for home and roaming users
Posted by Mike D at 8/23/2007 2:34:04 AM
Hello, I have a scenario I'd like to put out and see if anyone can help. I have a windows 2003 R2 network with an internal and perimeter network, the internal is fully windows 2003 and all users have access to mapped drives on the file server, we also have exchange 2007 server. In the perimete...more >>

IIS 6.0 / Windows Server 2003 / access based on domain
Posted by Nick Dangr at 8/23/2007 12:59:50 AM
I'm working on a simple file sharing website for my company. We want all of our stores to be able to access the website, but only those stores. Each store uses a dynamic domain name (kind of like dyndns.org but a commercial one, which pegs its dns name down to for example: store1.commercia...more >>



Enable client certificate based authentication for certain urls
Posted by Kshitiz at 8/22/2007 10:04:03 AM
Hi All, I want to allow anonymous access to my webserver. However I want certain urls to be allowed only after client certificate based authentication. I read many documents on client certificate based authentication and access control. But I did not exact information I am looking for. T...more >>

IIS 6.0 Console Tree is not visible and appears after iisreset why
Posted by Manu at 8/22/2007 12:20:02 AM
Hi All, When ever i open my inetmgr iis 6.0 the console root tree structure is Invisible and becomes visible after i do iisreset. Can anyone please help me In finding out what could be the reason and how to trouble shot this issue. Thanks Manu. ...more >>

Access to the Ftp site
Posted by framm07 at 8/20/2007 6:38:01 AM
Hi, my situation is: 1 domain controller in a single domain Win 2003 R2. There is a web server that hosts a ftp server. The web server is a member server in the domain. I cleared the "Allow anonymous connections" option on the FTP Site Properties, because I want that only few domain users ...more >>

Internal Cert with IE7
Posted by Rick at 8/19/2007 10:46:00 AM
microsoft.public.inetserver.iis.security We are issuing an internal Cert on a website , which was working fine with outside users, using IE6, they just had to import once and that was it. With IE7 they install the cert, but they get warned everytime they go to the site and get the red URL bar ...more >>

AutoComplete Forms with IE
Posted by Anthony Pratt at 8/16/2007 6:08:07 PM
We have an internally developed application that uses forms to collect data from the customer. This information consists of sensitive information we don't want stored if the end-user (browser) has AutoComplete for Forms turned on in the browser. Isn't there a way to disable this functional...more >>

Client Certificate - Password Check
Posted by Mark Pfeifer at 8/16/2007 1:36:51 PM
Is there a way to determine if the certificate had a pin/password entered prior to submitting it to a site? That is, can I tell from the server side if the certificate is from a smart card with a pin or a soft certificate with a password? Thanks, Mark ...more >>

s it possible to force IIS to accept any certificate?
Posted by Stanko Milosev at 8/15/2007 5:01:45 PM
Hello, I am trying to configure IIS to accept any certificate, from anyone, is that possible? TIA! Stanko. ...more >>

IWAM_xxxxxxx A/C
Posted by DD at 8/13/2007 6:54:00 PM
For security reason, I need to disabled the IWAM_USxxxxxxxx INTERNET GUEST A/C,but disabled theaccount, the event log non stop showing the following error "DCOM got error "Logon failure: user account restriction. " and was unable to logon .\IWAM_USGSCW2000 in order to run the server: {3D14...more >>

401.3 ACL error after ColdFusion 7 install
Posted by Cwhitmore at 8/13/2007 12:56:01 PM
I'm running Windows 2003 R2 64-bit and had IIS 6 running fine until I installed Coldfusion MX7. Now I get 401.3 errors for any site that I try to access on that server. I verified that Domain Users, IIS_USR and IIS_Servername all have access to the directory \COLDFUSIONMX7\runtime\lib\ What...more >>

FrontPage User Logins
Posted by Marty Shifflett at 8/13/2007 8:08:02 AM
Okay I am not sure why I can't figure this out, but it has been a long time since I had to set up any users for FrontPage authoring of web sites. I have a web site running in IIS 6.0 on a Windows 2003 Server. I have configured the Server Extensions 2002 for the site and can log in remotely v...more >>

Microsoft CA & external SSL
Posted by Wilson at 8/11/2007 10:28:00 PM
Currently, we are using external party’s SSL certificate to secure our web sites but for our SSL VPN appliance, the vendor said that we could use Microsoft certificate. But I am not sure whether there is any impact between the two or the best way to set up the CA server, as I am new to Micro...more >>

Selected certificate was already installed to another server
Posted by Wilson at 8/11/2007 1:10:02 AM
I am trying to renew our SSL cert on the web server by clicking on the ‘Process pending certificate..’ option but it says that, ‘Selected certificate was already installed to another server,…’. I have renamed the certificate to .cer and double-click it to check that it is the valid ...more >>

IIS7: cannot access a database from a page with authentication on local webserver
Posted by Noël_Danjou_[noeld] at 8/9/2007 12:19:16 PM
Vista Ultimate / IIS7 MS Access 2000 database Hello, I have an .ASP page that requires authentication. I enabled Windows Authentication in IIS Manager > Authentication. For the database, I successfully completed the solutions and workaround in KB article at http://support.microsoft.co...more >>

IIS prompt for domain userid after server is hardened
Posted by newbie NO[at]SPAM work at 8/8/2007 9:30:01 PM
Hi, I have an issue where the IIS website prompt for domain userid logon after the server is hardening by setting the users and everyone group to read, execute and list for the following directories C:\ C:\winnt C:\winnt\system C:\winnt\repair C:\winnt\system32 C:\winnt\system32\confi...more >>

problem with adding second SSL certificate
Posted by KBing at 8/6/2007 6:18:05 AM
I am running IIS 6 (W2003 Standard server) and have 10 websites configured. All websites have unique host header values. Two of the sites I need SSL running. The first site has had SSL running since we built this system. I am needing to add the second website with SSL certificate. The pr...more >>

hide IP address ..
Posted by davers232 NO[at]SPAM googlemail.com at 8/5/2007 9:35:06 AM
We have an ISA server providing NATted IP addresses to client computers. I see from www.whatismyproxy.com that the local IP address can be seen from the Internet, even using a proxy. How can I make browsing anonymous. 1 your computer 10.*.*.** 2 IP address seen: ***.**.***.** 3 Your external...more >>

Web server Security Issue
Posted by buc at 8/3/2007 7:31:01 PM
I have set up WEB server (Windows 2003 SP2 with IIS) to host a site. While looking through the security events audit. I noticed a large number of FAILURE AUDITS with the MICROSOFT_AUTHENTICATION_PACKAGE_V1 and KRBTGT\ service. These audits have various logon user names like PETER, APPLE, ROOT, ...more >>

Can't get to the select "process the pending request..." page
Posted by Artunc at 8/2/2007 4:38:01 PM
Created a new certificate, received it from Verisign, but I can install it to IIIS It's supposed to say "process the pending request..." but I get the normal wizard options. Is there a way to get back to the "process the pending request..." page or I have to re-request the certificate. ...more >>

Can't access secure website
Posted by feraria at 8/1/2007 3:40:08 PM
Up until last month I have not been able to access a secure website consistenanly. There are times I am able to access this site and sign it but if I sign out and tried to go back in I receive a blank page. I have done the following to tried and resolve these problems: deleted all cookie, file...more >>


DevelopmentNow Blog