Groups | Blog | Home


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > may 2008

Use of anyonymous authenticaion during impersonation
Posted by Sudhanshu at 5/30/2008 2:15:00 AM
Hi, We are using our third party component for doing authentication and authorization with IIS6 web server on win2k3 X64 EE. Here we are using IMPERSONATION concept for this integration. Can anybody describe the required configuration which are needed at IIS 6 for successfully impersonat...more >>


check SSL installation
Posted by Tony WONG at 5/29/2008 12:34:12 PM
i can view the page at port 80 http://XXX.com/testpage.html i set the web testpage to SSL at IIS (secure communication, tick require ssl & 128 bit) then i view this URL path https://XXX.com/testpage.html the IE return "cannot display the web page" 443 port has no problem cos it is inte...more >>

SSL Cert for multiple servers
Posted by SJMP at 5/29/2008 6:01:01 AM
Currently I have 1 SSL cert for Exchange (expiring in October 08) I would like to purchase a certificate that would service Exchange (OWA/OUtlook Anwhere), Terminal Server, and a third server. Would someone please make a recommendation on the best and mose effecient approach to serving al...more >>

View active connection
Posted by Sunny at 5/28/2008 10:20:00 PM
Hi all, Does it has any way to veiw the active connection from the remote PC to the IIS? For example, could it show the computer name of the remote PC if it opens any HTTP connection on the IIS? many thanks, Sunny...more >>

II7 - Sending Errror Messages to the Browser
Posted by Travis McGee at 5/28/2008 12:07:31 PM
Even though I have configured the IIS 7.0 (Windows 2008) properly to send errors to the Browser, somehow it just does not work. The only thing I get in the browser is : 500 - Internal Server Error - for ..asp pages. It does write into the logs fine with ....line number of the error, etc. but...more >>

Integrated Authentication Issue
Posted by Adrian Henke at 5/26/2008 3:03:02 AM
Hello On our webserver I configured the default website to allow "integrated authentication" only. Now if I try to visit the website, no matter from what destination from within the domain, I get an access denied error when trying to log in. The security event log shows failed authentication...more >>

IIS 7.0 Handler Mapping permission: Write
Posted by BPF (Brian and Paul Fan) at 5/24/2008 9:33:12 AM
Hello: In IIS 7.0, you can edit a handler mapping in the Handler Mappings applet (like for AspClassic), then click Request Restrictions button, Access tab, and select the "Write" permission. But even when the "Edit Feature Permission" in that site/folder is set to Read+Script+Execute, the ...more >>

certificate mapping auth problem
Posted by ArnisG at 5/23/2008 1:42:42 PM
Hi all! I have a website configured to authenticate users using certificate mapping. Athentication works fine with certificates issued from our old enterprise root CA. We have recently installed new PKI infrastructure with an offline root CA and enterprise subordinate (issuing) CA. When I t...more >>



How about TS?
Posted by straightup at 5/22/2008 7:59:35 PM
David, to what extent have you ever applied PhoneFactor to Terminal Services? Any special considerations?...more >>

SSL with & without www
Posted by Bill Board at 5/22/2008 9:27:50 AM
If I go to a site that is https with the www on the URL no issues. If I go there without the www I get a certificate warning. What gives? Thanks, Bill ...more >>

Multiple SSL Certificates for 1 web site
Posted by John - JDI at 5/21/2008 6:02:06 AM
Note -- some background, question at end. I am using OWA for both internal and external people. I have two different ways I want to access the site: 1) webmail.mydomain.com/exchange 2) servername/exchange Before I installled the CA signed certificate for webmail.mydomain.com I had...more >>

IIS on domain controller
Posted by OM at 5/20/2008 1:55:05 PM
Hi, I heard many comment about not putting IIS on a domain controller. Can someone tell me what is the implication of it? Thanks...more >>

Integrated windows security HTTP500 error
Posted by Linda at 5/20/2008 1:13:22 PM
I'm installing a webapplication on win2003 server. As soon as I enable the 'Integrated windows security' I get a very strange error: - accessing the website from a PC within the network, doesn't work (HTTP500 The page can not be displayed) - accessing the website from outside the network, usin...more >>

Integrated authentication FQDN issue
Posted by Russ at 5/19/2008 7:29:32 PM
Windows 2000 server running IIS has static IP and is in a Windows 2000 domain, "corp.com". IIS default website is configured to use integrated authentication User running Internet Explorer 6/7 browses to http://server and authenticates with no issue. User running Internet Explorer 6/7 brows...more >>

HELP! - I need to setup a temporary IIS redirect while I fix SQL Injection vulnerabilities on my site
Posted by dsa157 at 5/17/2008 2:23:53 PM
Hi all - My site has been hot by the latest wave of SQL Injection attacks. I (sorta) understand what I need to do to fix things, but it is going to take a *lot* of work that'll be pretty time consuming as the site is a hodge podge of classic ASP and ASP.Net and hand rolled scripts etc. What...more >>

LDAPS
Posted by SandpointGuy at 5/16/2008 10:25:00 AM
I have an IIS6 site running asp.net 2, and we are using Windows Integrated Security. As you know, we just check a box, there is no more IIS configuration beyond that. Some of our security people want us to use LDAPS, not just LDAP, to talk to AD (the assumption being IIS talks to AD via LDAP)...more >>

Contacts
Posted by Eric at 5/15/2008 8:17:01 PM
Users cannot right mouse click on email address and add to contacts in OWA. Forbidden 403 http internet explore. Receive error Type: Application, Event Type: Error, Event Category: Kernel Rule, Event ID:256 Computer: Mail. The Process C:\windows\system32\inetsrv\w3wp.exe (as user NT AUTHORITY\...more >>

Special Permission on IIS Box
Posted by Curt at 5/15/2008 2:23:01 PM
What permissions are granted to Everyone group via the following permissions: _______ Special Cfo/Ad,Cfi/Wd Can find anything on the web or MSDN that explains what this grants or if needed related to annoymous IIS access....more >>

Recovering from SQL Injection
Posted by YDelRosso at 5/15/2008 1:08:01 PM
I smacked around the web designer, he changed his code, we cleaned up the DB, and I thought all was right with the world. Enter cached pages on search engines.... It took a simple e-mail to Yahoo and an online form for Google. But I cannot get Microsoft Live Search to remove cached entries t...more >>

Certificate importing to Vista IE 7 using vbscript
Posted by Thajuonline at 5/14/2008 1:37:00 AM
hi, i m using the following script for importing my certificate into trusted root authority of IE and it is working fine for ie6 and ie7 in XP but it is not working in vista ie7.what can be the problem.is there any solution <SCRIPT language="VBSCRIPT"> on error resume next Dim Str, CEnr...more >>

sql injection
Posted by Alberto Brivio at 5/13/2008 1:55:30 PM
Dear All, I'd like to know what we can do against sql injection, in sql2003 and iis6.0 environment. Does exist a sort of tool able to filter inpunt url string in order to stop this kind of sql injection? Regards ...more >>

Permissions issue with virtual directory connected to a network sh
Posted by MosesBunting at 5/13/2008 12:25:00 PM
Hoping to get some help with a permissions? error we are getting. I'm not a very technical person, so please bear with me. Our intranet site defaults to allow anonymous access. There is a virtual directory defined (with anonymous access turned off) that connects to a secure network share....more >>

"This Page Contains Both Secure and Nonsecure Items"
Posted by E-Double at 5/13/2008 9:48:03 AM
Not sure if this is a post for the IIS forum or the IE forum, but every time we visit a certain page on our own IIS 6 Website with an SSL certificate installed IE 6 gives us the error "The following page contains both secure and unsecure items.' No other browsers (eg Firefox, Safari, etc...) ...more >>

a WWW-Authenticate header field that the server is not configured
Posted by Patrick at 5/11/2008 2:39:01 AM
Hi All, I have IIS6.0 website for which I wish to use SSL encryption. I did the following to secure it. 1. II've set SSL port to 4043. I have another app (App A) using port 443. 2. I secured the Application Directory using a Enterprise Root CA which I created for App A (using built-in MS ...more >>

HTTP 401.1 - Unauthorized: Logon Failed
Posted by Eric at 5/6/2008 4:48:00 PM
Hi all, I have downloaded ISS 5.1 and created a local server, however when trying to access it I get the error HTTP 401.1 - Unauthorized: Logon Failed Internet Information Services I have WinXP Pro SP2 I have tried various solutions via google, including article 896861, which spoke of...more >>

Pass Authentication Token between Websites
Posted by Matt at 5/5/2008 1:58:04 PM
Is there a way to transfer an authenticated user token (and session with redirect) from an ASP.NET 2.0 application (using Forms based or Basic Authentication against AD) to a different ASP.NET2.0 application. The different ASP.NET applications will be on different physical machines. I would ...more >>

REQUESTING A CERTIFICATE FROM THE CERTIFICATE OF AUTHORITY
Posted by CHANGING FAIL OVER CLUSTER TO NLB at 5/5/2008 12:01:01 PM
Hello: Novice to asp development. Hence, need help. When requesting a certificate from the CA server, one has to type in http://servername/certsrv in the url of the browser. I am wondering whether this page can be customized? If so, could please let me know how? Do I need to use ASP.NET...more >>

IWA problem
Posted by sjs at 5/1/2008 8:34:23 AM
I have an internal-only web app which I want to use a Windows Integrated Security to control access. Using IIS 6 I setup the Properties - Directory Security - Authentication and Access Control ensuring Anonymous Access is NOT checked and Integrated Windows Authentication is checked. I gave...more >>


DevelopmentNow Blog