Re: How to create file on network share from ASP.NET

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi, Andre.

You can use "mirrored" local accounts (that is, accounts with matching
usernames and passwords on two computers). You need to use this
approach when the computers are in separate domains with no trust
relationship or when the computers are separated by a firewall and you
cannot open the ports required for NTLM or Kerberos authentication.

See :
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secmod/html/secmod15.asp

In the "ASP.NET Worker Process Identity" section
you'll find precise instructions for setting up mirrored accounts.




Juan T. Llibre
ASP.NET MVP
http://asp.net.do/foros/
Foros de ASP.NET en Español
Ven, y hablemos de ASP.NET...
======================

"Andre" <Andre@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:84A1C352-478E-46BF-B8C6-931BCE67BB94@xxxxxxxxxxxxxxxx
> Guys,
>
> Thank you very much for your answers/suggestions.
>
> Scott,
> Does you suggestion mean that Windows will always try to login using current
> (impersonated) credentials first? What if my impersonated credentials are
> domain related, is it going to be a problem? Sorry for dumb questions I am
> not an expert in Windows security.
>
> Kevin,
> Does you suggestion mean, that it is domain, which webserver belongs to, you
> are talking about? Can impersonte user of another domain (I have domain name,
> username and password for that domain, but server is not part of that domain)?
>
> Juan,
> There are various reasons (not of a technical matter) which prevent our
> web-server to be joined with the other domain. Machines are on the same
> physical network, but webserver is maintained by one company and domain by
> another. So all I have from the domain managed box is the domain name, share
> name, username and password on THAT domain and I need to create export files
> using those credentials. I can do this from Windows GUI - access that share
> using provided credentials so it is should not a problem via .Net too.
>
> I am currently looking at using WNetAddConnection2 function to map external
> drives locally and write onto local drives. Is it a good idea?
>
> Thanks & Regards,
>
> Andre.
>
>
> "Scott Allen" wrote:
>
>> One technique I've used in the past is to use mirrored account. Set up
>> an account on both machines - same username, same password. Then
>> ASP.NET can impersonate the account on the server and be authenticated
>> / authorized on the remote machine.
>>
>> --
>> Scott
>> http://www.OdeToCode.com/blogs/scott/
>>
>>
>> On Thu, 21 Jul 2005 06:35:05 -0700, "Andre"
>> <Andre@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>>
>> >Hi Juan,
>> >
>> >Thank you for your reply, but my point is exactly that both computers ARE
>> >NOT members of the same domain - one is standalone Win2003 and another is
>> >external domain member and I can not put both onto the same domain. Is there
>> >any other way to do it?
>> >
>> >Thank you.
>> >
>>
>>


.



Relevant Pages

  • Re: Active Directory Value Proposition
    ... Two or 3 computers? ... Central administration of accounts, permissions, and policy. ... What are the risks? ... > Would you recommend using Active Directory in a small-business setting? ...
    (microsoft.public.win2000.active_directory)
  • Re: ISA Monitor Shows Traffic from Computers that are powered off !
    ... on which we have ISA 2004 installed. ... Employees leave at 5:00pm and switch off their computers. ... Client computers should never have exposed ports. ... anymore since the trojan probably knows all of your accounts. ...
    (microsoft.public.isa)
  • Re: Script help
    ... A community college I used to teach night classes at (in southwest Kansas, ... I'm just glad that it wasn't my network to ... >> computers and how much routine maintenence you want to perform on them, ... >> shared on a server somewhere on campus, then yes, individual accounts are ...
    (microsoft.public.windows.server.scripting)
  • Re: Install new hardware for SBS 2003
    ... I think he prefers this way because the aren't many user accounts and mailboxes plus it would appear he is not worried about NTFS permissions. ... His original outline did not mention file permissions either way, nor did it mention that he was aware that he'd have to rejoin the computers to the domain. ... I don't think we are disagreeing here, but I did want to make sure that he was aware of the drawbacks to his plan. ... Other than simply copying the data over I will have to get the current Exchange mail over too. ...
    (microsoft.public.windows.server.sbs)
  • Re: unable to add machine accounts to domain
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... * This posting is provided "AS IS" with no warranties and confers no rights! ... computers container to the NEW OU. ... Redirusr.exe (for user accounts) and redircomp.exe (for computer ...
    (microsoft.public.windows.server.active_directory)