Solved

authentication problems with IIS6 virtual directory from shared folder

Posted on 2009-07-01
2
752 Views
Last Modified: 2013-12-08
Hi Experts!,

I configured a virtual directory in IIS6 with a shared folder, but when i access to this files, i dont´ have the same permissions that the NTFS security in the shared folder.
When i open through IE the virtual directory with my domain user i can see everyting (files and folders) and i should not have access. The only authentication method used is Integrated Windows Authentication.

What is the best practices to configure the autentication in virtual directory whit shared folder?
thanks!
0
Comment
Question by:at_user
2 Comments
 
LVL 22

Accepted Solution

by:
cj_1969 earned 500 total points
ID: 24763217
The easiest thing to do is to change the anonymous ID on the security tab to an ID that has permissions to access the directory.
There
The problem you are running into is a security issue with MS servers and passing credentials from the browser to the IIS server to the file server, "3 stage" authentication.  
There are three ways that you can make this work ...
1. You can do as I suggested and over ride the anonymous ID so that it is the credentials from IIS that are used to authenticate to the file server,
2. Enable basic authentication on the directory/site.  This will pass the ID and PW in clear text from the browser to the IIS server which will allow the credntials to then the passed to the file server.  This should only be done if using SSL to encrypt the communications stream to protect the credntials.
3. Enable Kerberos authentication between the IIS and file servers.  Kerberos authentication is only thing that will allow the credentials to be passed in encrypted form from the client to the intermediate server and then from the intermediate server to the third server.  It does this by passing the Kerberos authentication token and not the credentials themselves.  BUT ... to do this means AD changes to allow the IIS server to have delegation rights to AD so that it can validate the token before passing it on.  Enabling the file sharing service on the file server as a an available service so that the Kerberos credentials can be used to authenticate and gain access to this resource.

So ... my recommendation ... use a known account to over-ride the anonymous credentials for this VD.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Several part series to implement Internet Explorer 11 Enterprise Mode
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now