Solved

authentication problems with IIS6 virtual directory from shared folder

Posted on 2009-07-01
2
756 Views
Last Modified: 2013-12-08
Hi Experts!,

I configured a virtual directory in IIS6 with a shared folder, but when i access to this files, i dont´ have the same permissions that the NTFS security in the shared folder.
When i open through IE the virtual directory with my domain user i can see everyting (files and folders) and i should not have access. The only authentication method used is Integrated Windows Authentication.

What is the best practices to configure the autentication in virtual directory whit shared folder?
thanks!
0
Comment
Question by:at_user
2 Comments
 
LVL 22

Accepted Solution

by:
cj_1969 earned 500 total points
ID: 24763217
The easiest thing to do is to change the anonymous ID on the security tab to an ID that has permissions to access the directory.
There
The problem you are running into is a security issue with MS servers and passing credentials from the browser to the IIS server to the file server, "3 stage" authentication.  
There are three ways that you can make this work ...
1. You can do as I suggested and over ride the anonymous ID so that it is the credentials from IIS that are used to authenticate to the file server,
2. Enable basic authentication on the directory/site.  This will pass the ID and PW in clear text from the browser to the IIS server which will allow the credntials to then the passed to the file server.  This should only be done if using SSL to encrypt the communications stream to protect the credntials.
3. Enable Kerberos authentication between the IIS and file servers.  Kerberos authentication is only thing that will allow the credentials to be passed in encrypted form from the client to the intermediate server and then from the intermediate server to the third server.  It does this by passing the Kerberos authentication token and not the credentials themselves.  BUT ... to do this means AD changes to allow the IIS server to have delegation rights to AD so that it can validate the token before passing it on.  Enabling the file sharing service on the file server as a an available service so that the Kerberos credentials can be used to authenticate and gain access to this resource.

So ... my recommendation ... use a known account to over-ride the anonymous credentials for this VD.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
Do you come here a lot? Are you lazy like me and don't want to go through the "trouble" of having to click your Dock's Safari icon and then having to click your Experts Exchange Favorites bookmark to get here? Well then this article is for you.
This Micro Tutorial will demonstrate how to add subdomains to your content reports. This can be very importing in having a site with multiple subdomains.
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now