Authentication in .NET..... pointers

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Paul (prx1988_at_hotmail.com.invalid)
Date: 02/15/04


Date: Sun, 15 Feb 2004 00:02:05 +0000

Background.

We have a corporate intranet that is (as much as makes no difference)
entirely IIS web servers & IE browsers. We use a standard Windows
domain logon and use active directory. We also have a "standard" user
(like a guest one) that has few privileges.

Web pages are secured and authenticated by manipulating the permissions
on the files and folders within the web. This has been the situation
for a number of years and is relatively set in stone. We use challenge
response to authenticate for web pages.

If a user logs on as the std user and tries to access a web page to
which they have no access, a login box appears. If they are really a
user with the correct credentials they can enter their userid/passwd at
the prompts. As I understand it, it isn't possible to revoke that
authentication (ie for that user to log off and revert to the std user)
without closing down IE and any other browser windows that the user may
have opened whilst "logged on." Is that correct?

Assuming that is correct, how would we manage the following. Imagine an
operation that needs two users to authorise it at the time it happens
(eg a second nurse witnessing the administration of a medicine in a
hospital, or a superviser check on a large transaction.) How could that
second person's credentials be checked against their windows domain
login and subsequently cancelled? Is there really no way to cancel the
1st user's logon either?

I'm fairly new to this so would appreciate some pointers.... i've
pondered with creating session variable "tokens" and all sorts of
things, but would like a nudge in the right direction before I get too
embroiled in all this as the inability to revoke the authentication
always seems to end up scuppering any idea that I have :(

Thanks

-- 
Paul


Relevant Pages

  • Re: VPN to Windows Network with ACE/SecurID
    ... I figure you've probably reached out to the RSA Tech Support guys for ... RSA's new SecurID for Windows infrastructure ... With the RSA Authentication ... Domain logon and the local PC logon. ...
    (microsoft.public.win2000.security)
  • Re: Change in ASP.Net authentication between Win2000 and Win2003
    ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
    (microsoft.public.windows.server.security)
  • Re: Change in ASP.Net authentication between Win2000 and Win2003
    ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: form authentication and webservices
    ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... We will be using Windows Authentication on the Web Services side (same ... Dominick Baier ...
    (microsoft.public.dotnet.framework.aspnet.security)