Solved

FTP 7.5 Authentication ASP.NET membership Problem

Posted on 2010-09-21
1
1,447 Views
Last Modified: 2013-12-02
I'm running a Windows 2008 R2 server with IIS and FTP 7.5.  I want to use ASP.NET membership authentication to authenticate FTP users.

Followed this article for configuration: http://learn.iis.net/page.aspx/389/configuring-ftp-with-net-membership-authentication/  I'm using a SQL authentication connection string since connecting from a DMZ web server through firewall to SQL server.  Using FTP 7.5 (64-bit site) with SQL 2008 as backend.  The ASPNETDB database is configured and IIS Manager can add and remove .NET users and roles to it without issue.  The issue comes when trying to initiate an FTP connection.  In IIS, the user has been granted privileges to the FTP site (Authorization Rule), Forms authentication is enabled, and FTP Authentication has been configured (all per the article), however, when a FTP connection is attempted, the FTP client returns error "530 User cannot log in" after the USER and PASS commands.  It shows the same in the FTP server logs:

2010-09-21 18:31:04 172.16.1.1 - 192.168.3.1 21 USER ftpuser 331 0 0 a851d7ec-e431-4295-9b23-031b03699371 -
2010-09-21 18:31:04 172.16.1.1 - 192.168.3.1 21 PASS *** 530 2148734217 41 a851d7ec-e431-4295-9b23-031b03699371 -
2010-09-21 18:31:04 172.16.1.1 - 192.168.3.1 21 ControlChannelClosed - - 0 0 a851d7ec-e431-4295-9b23-031b03699371 -

The login attempts are not iterating in the ASPNETDB table.  In fact, the application pool is not attempting to contact the membership database in SQL.  I confirmed this with SQL Profiler and Wireshark.  I expect the asp.net membership to authenticate the user by talking to the SQL server, but that's not happening.  Windows authentication is not an option due to the firewalled environment.  I've searched many articles, but I've not found a solution.  Nothing in event viewer.  I tried using ProcMon to see if any file or folder access problems....don't see any.  I also confirmed that I could authenticate via an aspx login page using the same user and password with forms authentication, which succeeded..  So, it's only the FTP part that won't authenticate through asp.net membership.  Here's the configuration section from the web.config (connection string excluded):

<membership defaultProvider="FtpSqlMembershipProvider">
         <providers>
            <add name="FtpSqlMembershipProvider"
               type="System.Web.Security.SqlMembershipProvider,System.Web,Version=2.0.0.0,Culture=neutral,PublicKeyToken=b03f5f7f11d50a3a"
               connectionStringName="FtpMAG1603SQLServer"
               enablePasswordRetrieval="false"
               enablePasswordReset="true"
               requiresQuestionAndAnswer="false"
               applicationName="/"
               requiresUniqueEmail="false"
               passwordFormat="Hashed"
        minRequiredPasswordLength="7"
               minRequiredNonalphanumericCharacters="1"
  maxInvalidPasswordAttempts="50"
        passwordAttemptWindow="10" />
         </providers>
      </membership>


      <roleManager defaultProvider="FtpSqlRoleProvider" enabled="true">
         <providers>
            <add name="FtpSqlRoleProvider"
               type="System.Web.Security.SqlRoleProvider,System.Web,Version=2.0.0.0,Culture=neutral,PublicKeyToken=b03f5f7f11d50a3a"
               connectionStringName="FtpMAG1603SQLServer"
               applicationName="/" />
         </providers>
      </roleManager>


FTP authentication has the Custom provider "AspNetAuth" enabled per the configuration article mentioned in the beginning of the post.  It seems there may be a missing connection between this provider and the custom providers configured above.  The article I followed assumes the SQL database is on the local host and it's using Windows Authentication, but I'm doing just the opposite...remote SQL with SQL authentication.  There's a section of the article that talks about giving the Application Pool identity permission to SQL, but I obviously can't do that in a DMZ/firewalled environment.  Also, Network Service is no longer used in Windows Server 2008 R2.  

 I verified the firewall wasn't causing the issue by disabling it.  Please give any insight possible.  Thanks.
0
Comment
Question by:Russell64
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 

Accepted Solution

by:
Russell64 earned 0 total points
ID: 33784002
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 2008 R2 File Share 8 51
Concerns if raising functional levels for domain/forest that includes RODC in DMZ? 6 46
DNS Replication 12 69
Can't connect to FTP 18 101
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question