Solved

authentication problems with IIS6 virtual directory from shared folder

Posted on 2009-07-01
2
759 Views
Last Modified: 2013-12-08
Hi Experts!,

I configured a virtual directory in IIS6 with a shared folder, but when i access to this files, i dont´ have the same permissions that the NTFS security in the shared folder.
When i open through IE the virtual directory with my domain user i can see everyting (files and folders) and i should not have access. The only authentication method used is Integrated Windows Authentication.

What is the best practices to configure the autentication in virtual directory whit shared folder?
thanks!
0
Comment
Question by:at_user
2 Comments
 
LVL 22

Accepted Solution

by:
cj_1969 earned 500 total points
ID: 24763217
The easiest thing to do is to change the anonymous ID on the security tab to an ID that has permissions to access the directory.
There
The problem you are running into is a security issue with MS servers and passing credentials from the browser to the IIS server to the file server, "3 stage" authentication.  
There are three ways that you can make this work ...
1. You can do as I suggested and over ride the anonymous ID so that it is the credentials from IIS that are used to authenticate to the file server,
2. Enable basic authentication on the directory/site.  This will pass the ID and PW in clear text from the browser to the IIS server which will allow the credntials to then the passed to the file server.  This should only be done if using SSL to encrypt the communications stream to protect the credntials.
3. Enable Kerberos authentication between the IIS and file servers.  Kerberos authentication is only thing that will allow the credentials to be passed in encrypted form from the client to the intermediate server and then from the intermediate server to the third server.  It does this by passing the Kerberos authentication token and not the credentials themselves.  BUT ... to do this means AD changes to allow the IIS server to have delegation rights to AD so that it can validate the token before passing it on.  Enabling the file sharing service on the file server as a an available service so that the Kerberos credentials can be used to authenticate and gain access to this resource.

So ... my recommendation ... use a known account to over-ride the anonymous credentials for this VD.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This Micro Tutorial will demonstrate how to add subdomains to your content reports. This can be very importing in having a site with multiple subdomains.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question