IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old September 12th, 2006, 06:28 AM
rb96 rb96 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2006
Posts: 2 rb96 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 8 m 35 sec
Reputation Power: 0
Authentication options?

I'm currently reviewing options for authentication of remote users as part of a web based portal (IIS). The user base will be up to few hundred. Requisite user data includes: username, password, surname, forenames, telephone, company, email, applications allowed etc. Password policy dictates that I should ensure passwords are changed every 30 days. Any system must also be managable via a web browser.

Ideas modelled so far:
> Script-level (ASP) protection supported by an Access database containing user accounts, passwords etc. Considered to be inadequate as applications include non-script content (e.g. Word documents images) which needs to be protected.
> Use of basic authentication. Creation/management of Windows user accounts/groups using ADSI (WinNT provider). Group permissions assigned to various application directories in wwwroot. Due to WinNT being non-extensible I created a parallel Access database to store requisite user data.

The ADSI solution I have devised works, however my concerns are as follows:
> Users are elevated to possess Windows accounts.
> Scalability/performance.
> Immediacy of updates.
> Unclear how to approach password refresh requirement.

Useful advice/recommendations would be greatfully recieved.

Regards,


Rob.

Reply With Quote
  #2  
Old September 12th, 2006, 07:22 AM
jharnois's Avatar
jharnois jharnois is offline
mod_dev_shed
Dev Shed God 20th Plane (14500 - 14999 posts)
 
Join Date: Sep 2002
Location: Atlanta, GA
Posts: 14,569 jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 2 Days 22 h 42 m 51 sec
Reputation Power: 835
I wouldn't use Access for a website of any size. Access doesn't share well. Step up and use SQL server or even MySQL if you can't afford SQL server.

You can protect non web-based documents with a script level authentication system. Put the documents outside the web root and have the script initiate the download after validating the user.
__________________
# Jeremy

Explain your problem instead of asking how to do what you decided was the solution.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Authentication options?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT