Question

Authenicating with Sharepoint team service 3.0

Asked by: marrowyung

Dear all,

I want to setup the Sharepoint team service 3.0 to authenicate with SQL server 2005 login for security sick, anyway to do it?  modify the web.config files?  please advice how can I do modify the original one.

The reason I do it is because I find the form and SSO authenication doesn't work and only windows NTLM works but I don't want that, this will only use the login on that local machine.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-10-03 at 04:28:03ID24782291
Topic

MS SharePoint

Participating Experts
2
Points
500
Comments
26

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Authenication
    Is this possible with ASP? I'm new to ASP, but learning. I have read about using asp to not cache webpages, well my problem runs along those lines. I have anonymous authenication setup on my specific asp pages on my webserver (IIS) to control security, well you login in on...
  2. Unabled to authenicate using RPC over HTTP
    Here we go another RPC over HTTP question. First of all I have successfully set this up on another server and now doing it again I'm having trouble authenicating using NTLM RPC component installed, Exchange enabled and rebooted for RPC. RPC edited in IIS annon unchecked basic...
  3. authenications
    I have an aspx page that the users will login into and be authenicated against a users table in sql database. I want to stop users from loading other pages from the website without first logging in to the site. Any help would be greatly appreciated. I already have the cookie...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: zephyr_hexPosted on 2009-10-05 at 16:04:38ID: 25500673

 

by: marrowyungPosted on 2009-10-05 at 21:46:34ID: 25501959

Dear Zephyr_hex,

Are all these only apply to Sharepoint server 2007 but not Sharepoint team service 3.0 ?

 

by: tedbillyPosted on 2009-10-05 at 23:15:25ID: 25502207

Sharepoint uses Windows Authentication by default which is VERY secure.  The background services should be configured to use domain service accounts.  Form Based Authentication is actually less secure unless you use SSL (which slows the site) and many features don't work with it.

If your client computers are on the same domain as the Sharepoint server use the default Windows Authentication.  It's secure and fast.

 

by: zephyr_hexPosted on 2009-10-06 at 08:51:36ID: 25506437

authentication in sharepoint 2007 is the same as WSS 3.0  (what you're calling sharepoint team services 3.0).

WSS 3.0 is the core of sharepoint 2007.  sharepoint 2007 adds extra functionality... but the authentication methods are not different.

 

by: marrowyungPosted on 2009-10-06 at 21:25:45ID: 25512209

tedbilly,

Right now the point is the user account is stored locally on the sharepoint team service server, which is in the DMZ, I don't think it is secure enought!

I can't see it prompt the domain when logging in.

 

by: tedbillyPosted on 2009-10-07 at 12:43:38ID: 25519171

Sorry, I disagree.  Sharepoint only stores the user SID.  I don't see the security risk you seem to be concerned about.  Sharepoint doesn't store any user credentials.  The SID has to be generated using the on the fly NTLM authentication process which is already encrypted.

 

by: tedbillyPosted on 2009-10-07 at 12:45:01ID: 25519196

Note: With Windows Authentication if the client system is in the same domain as the Sharepoint server, IE will sign in using NTLM automatically without a prompt.  This is also true if the site is marked as 'Trusted' with the 'Automatically Login' option selected.

 

by: marrowyungPosted on 2009-10-08 at 04:03:00ID: 25523937

Dear Tedbily,

This sharepoint service will use local login acount and we don't user domain login.

the user will be internet users.

How about that? How can you verify that that login is very secure, how many bits of encrption it use?

 

by: zephyr_hexPosted on 2009-10-08 at 08:38:07ID: 25526655

if your users are internet and not intranet users, then FBA with SSL is probably the way to go

 

by: tedbillyPosted on 2009-10-08 at 21:17:25ID: 25532263

If you want to use 'Form Based Authentication' here is a starting point: http://www.codeplex.com/fba

As zephyr_hex recommended use SSL for the log in page.

Do not use SQL accounts for the Sharepoint services and be sure to use a local login account.

 

by: marrowyungPosted on 2009-10-08 at 21:43:11ID: 25532357

tedbilly,

The main objective is do not use local login account in that local Sharepoint team service account.

But as far as I konw, the FBA comes from Sharepoint team server 3.0 doesnt' works, I tried that, the same login account and password used in Windows Authenication doesn't work. So that only way is to use www.codeplex.com/fba?

for intranet user, I agree to use domain login of course as it is NTLM, but the main point is it is not released to public and it is already very secured.

Yeah, SSL of course, for any kinds of internet based login page !

 

by: marrowyungPosted on 2009-10-08 at 21:43:49ID: 25532358

the one in http://www.codeplex.com/fba apply for shareteam service 3.0 also?

 

by: tedbillyPosted on 2009-10-08 at 21:50:03ID: 25532384

Well I've been told it will work but to be honest I've never tried it.

 

by: marrowyungPosted on 2009-10-08 at 21:54:38ID: 25532403

tedbilly,

Yeah, that one still in beta and in WSP format, I will try it and I am wondering !

But if you try to setup sharepoint team service for external staff need to login from internet/from home, what authenication method will you use?

that codeplex, someone tell me this also, I am afraid that it is some kind of application back door from security point of view.

 

by: tedbillyPosted on 2009-10-08 at 22:00:52ID: 25532429

IMHO I'd never expose a corporate website that staff can use to the internet.  Our remote staff use secure VPN and/or RDP.

 

by: marrowyungPosted on 2009-10-08 at 22:07:36ID: 25532455

tedbilly,

VPN is good. This might not a company's web site but a workspace for staff to work from home! We also need  antivirus tools for anything upload to this workspace also.

Your case is VPNed to it and then open the intranet web site, right? so the end to end connection is encrypted, right?

 

by: marrowyungPosted on 2009-10-11 at 22:44:02ID: 25548785

tedbilly,

Do you know if I have to use the codeplex to work, do I need to create a separate database to store user login name ? using http://technet.microsoft.com/en-us/library/cc262350.aspx#section2 ?

 

by: tedbillyPosted on 2009-10-11 at 23:15:46ID: 25548874

Yes VPN can be encrypted and yes once the VPN connection is established they simply use the intranet like they would if they were at work.

If use use secure VPN you can simply use the default Windows Authentication without any extra work.

If you use 'Forms Based Authentication' and a SQL authentication provider then yes you'd need a SQL database to store the logins.  However, I'd avoid this if you can.  Windows Authentication is a better choice for Sharepoint because all features are supported in Sharepoint with it.

 

by: marrowyungPosted on 2009-10-16 at 08:48:16ID: 25590626

Dear tedbilly,

OK, you mean don't use FBA as long as it is really needed, but for internet user, FBA with SSL is necessary, right?

Then what I am thinking is how/where to store to userID, How to intergrate the FBA with the DB created by using http://technet.microsoft.com/en-us/library/cc262350.aspx#section2?

 

by: tedbillyPosted on 2009-10-18 at 20:50:08ID: 25602541

Based on your requirements I feel that 'Form Based Authentication' isn't a good choice.  I'd use Windows Authentication with secure VPN.  FBA has many problems with Sharepoint.

Even if your staff work from home to access a corporate website on the internet I would still use Windows Authentication with SSL because it's more secure.

 

by: marrowyungPosted on 2009-10-23 at 02:57:47ID: 25642768

Tedbiliy,

For your comment: "Even if your staff work from home to access a corporate website on the internet I would still use Windows Authentication with SSL because it's more secure.", this is for FBA, right?

What is the problme you found out for FBA? the white paper say this also but it just say problem, it didnt' sya what problem it is.

if our staff don't have VPN, then your suggestion doesn't works, right?

 

by: tedbillyPosted on 2009-10-23 at 12:19:22ID: 25647458

Many features won't work with FBA.  Specifically the client integration.

Read the following from http://msdn.microsoft.com/en-us/library/bb975136.aspx#MOSS2007FBAPart1_Intro

Important:

When you use forms authentication, client integration is disabled by default because client integration does not natively support forms authentication. You might be able to use many client integration features with forms authentication, and there are workarounds available to implement varying levels of client integration functionality with forms authentication. Specifically, starting in the Office 2007 Cumulative Update for April 2009 (Microsoft Help and Support), Microsoft Office Word, Microsoft Office Excel, Microsoft Office PowerPoint, and Microsoft Office SharePoint Designer all have native support for forms authentication, as described in Forms Authentication in SharePoint Products and Technologies (Part 3): Forms Authentication vs. Windows Authentication. If you plan to use client integration with forms authentication, you must fully test any available solutions or workarounds to determine whether the performance and functionality are acceptable in your environment. Microsoft Customer Support can provide commercially reasonable support to help you troubleshoot published workarounds.
Deciding to Use Forms Authentication

Some organizations want to use Windows users and groups in SharePoint Products and Technologies, but enter credentials via forms authentication. Before using forms authentication, determine why to use forms authentication in the first place: What is the business driver? If user accounts are stored in a location other than an Active Directory domain controller, or if Active Directory is not available in a particular environment, using forms authentication with a membership provider is a good choice. But if you want to force logon only via forms authentication, but still use Windows and all of the integrated features it provides, you should consider an alternative such as publishing the SharePoint site with Microsoft Internet Security and Acceleration (ISA) Server 2006. ISA Server 2006 allows users to log on by using a forms authentication Web form, but treats them like Windows users after authentication. This implementation provides a more consistent and compelling experience for end users.

 

by: marrowyungPosted on 2009-11-04 at 07:25:17ID: 25740232

tedbilly,

As we said before, to use FBA for internet user only solution, we have to use SSL with this, am I right?

I dont' think we have to use ISA 2006 and I have read that link before, it doens't tells a lot and make me confuse.

 

by: tedbillyPosted on 2009-11-04 at 18:38:19ID: 25746294

Yes you should use SSL for the sign in page.  You don't have to use it for all pages with FBA.

I'm giving you the recommended strategies from Microsoft.  I'm sorry you don't understand the solutions however, I know that they are far safer than FBA, will perform better and allow you to use all features.

 

by: marrowyungPosted on 2009-11-18 at 02:36:39ID: 25848214

Tedbilly,

Thanks for this.

 

by: marrowyungPosted on 2009-11-18 at 02:37:12ID: 31636707

No

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...