Re: slow iis 6.0 performance

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Param R. (pr_at_nospam.com)
Date: 12/09/04


Date: Thu, 9 Dec 2004 11:10:13 -0600

I set the identity of the application pool to a domain user account. You are
referring to the setting on a per website level for anonymous connections.

thanks!

"Egbert Nierop (MVP for IIS)" <egbert_nierop@nospam.invalid> wrote in
message news:ubN$ivf3EHA.404@TK2MSFTNGP10.phx.gbl...
> "Param R." <pr@nospam.com> wrote in message
> news:%23E3F9BY3EHA.3236@TK2MSFTNGP15.phx.gbl...
>> So you would recommend running Web Servers outside the domain? Now
>> imagine a server farm. Wouldnt administration be a royal pain.
>
> not neceseraly
> In your domain controler, you set a server property where servers trust
> each other, so in SQL server, you can expect the IUSR account to be the
> same as NT AUTHORITY\ANONYMOUS LOGON
> on windows 2003 NT AUTHORITY\NETWORK SERVICE. But in this case, the SQL
> server should not be part of a local domain but dedicated to the
> webserver.
>
>
> ps: your prev. question. IIS_WPG on the DC is part of the DC policy and
> not part of the -domain policy- so if your webserver is -not- a DC, your
> IUSR account might suck performance.
>
> Cheers,
>
>> thanks!
>>
>> "Leythos" <void@nowhere.org> wrote in message
>> news:MPG.1c213957ea138acc989c1d@news-server.columbus.rr.com...
>>> In article <#Oo5tLW3EHA.3336@TK2MSFTNGP11.phx.gbl>, pr@nospam.com
>>> says...
>>>> Well what if the back-end database security is controlled by domain
>>>> user
>>>> accounts and if I need my web app to authenticate as a domain user
>>>> against
>>>> the database? In that case I would need to use some sort of
>>>> impersonation,
>>>> which is what it was designed to do in the first place..
>>>
>>> I know that you didn't wan to hear it, but if the users have domain
>>> accounts, then why not let them VPN into the network, or provide a
>>> secure server for them to access. I've never liked the idea of having a
>>> web server as part of the domain, and even with government systems we
>>> don't do it.
>>>
>>> Since you only mentioned DB access, there is nothing that you can't do
>>> with login/user information provided in the app, that you can't do with
>>> domain accounts.
>>>
>>> --
>>> --
>>> spamfree999@rrohio.com
>>> (Remove 999 to reply to me)
>>
>>
>



Relevant Pages

  • Re: Compromise?
    ... Yes, if you don't provide a password on your SA account, anybody able to run ... and connect now has complete control over your SQL Server. ... Server has. ...
    (microsoft.public.sqlserver.security)
  • Re: Windows Auth to SQL Server from ATL Web Service not working...
    ... account I'm logged on as. ... SQL on a different box from my web service in an Atl Server web ... impersonation token is not passed on to the SQL Server. ... Event Category: Account Logon ...
    (microsoft.public.vc.atl)
  • Re: Discussing 3 different strategies for deleting from multiple tables
    ... I will be using SQL Server but I am riding on top of a third party ... FYI, Account contains around 20K ... >>> This results in one parameterized query followed by two more trips to ...
    (microsoft.public.data.ado)
  • RE: connection problems in secondary site and SQL server
    ... Do you have a Windows 2003 server anywhere in your environment? ... i can't add this account to this group. ... SMS Management Point encountered an error when connecting to its Database ... SMS on SQL Server My_Primary_SMS_Server. ...
    (microsoft.public.sms.admin)
  • RE: MP Install issue
    ... Will setting the SPN on the domain account fix the communication issue ... >> MPDB ERROR - CONNECTION PARAMETERS ... >> with a trusted SQL Server connection. ...
    (microsoft.public.sms.setup)