Re: Security - Active Directory Good Practices

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




"Sandy" <Sandy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C898E039-2340-4597-BFF5-875E234CFE81@xxxxxxxxxxxxxxxx
Thanks for your reply, Ralph. Wouldn't putting Active Directory code
directly in the app make the network itself vulnerable?

I may be out in left field here, but it just seems to me it somehow isn't
a
"best practice." I would be more inclined to periodically dump the Active
Directory info into a Sql Server table and use stored procedures to access
that table for rights.

Also, in your experience, have you ever seen Active Directory code put
directly into code in a VB application?

--
Sandy


<snipped>

Yes, unfortunately I have. <g>

But the issue here isn't an absolute.

Besides the obvious - "There are three ways to do a job - the right way, the
wrong way, and the boss' way!" You need to ask yourself - Who are the
potential attackers? What is it I'm actually securing?

Is such a App less 'secure'? Yes.
Is the 'security risk' worth it? Maybe?
Is the App as 'secure' as it needs to be? This what defines whatever "best
practice" should be.

For example, I have seen incredibly complex security schemes employed to
protect viewing a particular datasource. Only to discover that the data was
an inhouse telephone directory, published once a month, and could be found
scattered about in the main lobby. <g>

An excellent book - a short read with a wealth of information and
appreciation of what "best practice" actually means is - "Secure Coding:
Principle & Practices", Graff & van Wyk, O'Reilly.

-ralph


.



Relevant Pages

  • Re: Security Exception when deploying a VB.NET 2003 Solution
    ... It runs fine on any workstation. ... folder 2 levels up from the BIN folder where the application resides. ... Microsoft .NET security errors upon trying to start the Executable. ... I bet the workstaion is WinXP and your app is trying to write data( ...
    (microsoft.public.vsnet.general)
  • Security: ASP.Net + SQL Server DNZ
    ... I am woking on an ASP.Net app that will be in the DMZ and SQL Server will be ... Using integrated security. ... Connection-string will need to include both uid and pwd. ... the app in a secure place, ...
    (microsoft.public.sqlserver.security)
  • Security: ASP.Net + SQL Server DNZ
    ... I am woking on an ASP.Net app that will be in the DMZ and SQL Server will be ... Using integrated security. ... Connection-string will need to include both uid and pwd. ... the app in a secure place, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Access 2002 Security on multiple workstations
    ... > I am trying to learn on the fly about Access Security for an app we ... I realize Access security is an advanced subject ... > I also have two Client PC's: Client1 and Client2 who use MyApp. ... You need to start over with the proper security FAQ documents and follow all ...
    (comp.databases.ms-access)
  • WM5 Security Queries
    ... the Security model in WM5. ... in the past but my app has been designed mainly for Pocket PCs and Pocket PC ... I have a Dell Axim X51v Pocket PC with WM5 and have been doing some testing ... While I am gradually coming to grips with the Security model, ...
    (microsoft.public.dotnet.framework.compactframework)