Security

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Demetri (Demetri_at_discussions.microsoft.com)
Date: 10/08/04


Date: Fri, 8 Oct 2004 12:35:02 -0700

I have a client that would like the asp.net application to have security as
follows:

Impersonated using account XXXXX for the purpose of using SSPI in making the
database connection. This way no user information is stored anywhere but IIS
security settings.

At the same time the app will be in need of capturing user NT credentials to
identify who is actually accessing the web application. The NT account itself
will not be set up in SQL server. So the app can not use integrated security.

Normally the web.config would have the db connection string using a db
defined user account. However, in this case we need the db user to be the
same user as the web app is running under yet we need the client user's NT
info.

Any help is appreciated.

-Demetri



Relevant Pages

  • RE: Event ID 529 on cleint workstation
    ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
    (microsoft.public.windows.server.sbs)
  • Re: How good is Comodo Internet Security?
    ... Admin account + web browser + LUA token ... admin account opposed of running as iam now, which is JUST PURE admin level? ... While LUA gives added security, ... payload delivered by a buffer overrun (assuming the app was allowed to ...
    (comp.security.firewalls)
  • RE: Using kerberosSecurity Throws Security Exception
    ... I am experiencing this error while trying to use a Windows XP client ... application to access a web service located on a W2k3 server. ... client app on the server, ... > Account with a Custom Principal Name using SetSPN.exe utility. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: One login, several environments to use?
    ... >to have one account per user, instead of one account for each client. ... >each client must preserve their aliases and other environment funnythings. ... Each member of the team needed to be able to access each app, ...
    (comp.sys.hp.hpux)
  • Re: One login, several environments to use?
    ... >>to have one account per user, instead of one account for each client. ... >>each client must preserve their aliases and other environment funnythings. ... > 1 app at a time. ...
    (comp.sys.hp.hpux)