473,396 Members | 1,775 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,396 software developers and data experts.

securing pages without windows login

Hi all,

Does anyone know of a way to, programmatically with script at the server,
reset the current user's security context from the IUSR_ account to a
different one? Ideally, what we'd do is anyone who is already logged in as
a customer through our ASP page login (setting customer-specific session
variables), we'd programmatically impersonate them as a different windows
account (switching them from the anonymous IIS account they start off as).
Bottom line is that we don't want them to have to login a 2nd time to get to
these new pages.

We've got other non-asp files that I cannot simply put behind an ASP-based
login, which is why we need to lock the directory down behind Windows
security.

Any thoughts would be appreciated! thanks,

Dan
Jul 22 '05 #1
3 1249
http://support.microsoft.com/default...b;en-us;248187

--
--Mark Schupp
Head of Development
Integrity eLearning
www.ielearning.com

"Dan August" <da*********@hotmail.com> wrote in message
news:ur**************@TK2MSFTNGP10.phx.gbl...
Hi all,

Does anyone know of a way to, programmatically with script at the server,
reset the current user's security context from the IUSR_ account to a
different one? Ideally, what we'd do is anyone who is already logged in
as
a customer through our ASP page login (setting customer-specific session
variables), we'd programmatically impersonate them as a different windows
account (switching them from the anonymous IIS account they start off as).
Bottom line is that we don't want them to have to login a 2nd time to get
to
these new pages.

We've got other non-asp files that I cannot simply put behind an ASP-based
login, which is why we need to lock the directory down behind Windows
security.

Any thoughts would be appreciated! thanks,

Dan

Jul 22 '05 #2
Dan
thanks, exactly what I was looking for .. I thought I had exhausted the MS
knowledge base, but you've proven me wrong :-)

Dan

"Mark Schupp" <no******@email.net> wrote in message
news:OZ**************@TK2MSFTNGP14.phx.gbl...
http://support.microsoft.com/default...b;en-us;248187

--
--Mark Schupp
Head of Development
Integrity eLearning
www.ielearning.com

"Dan August" <da*********@hotmail.com> wrote in message
news:ur**************@TK2MSFTNGP10.phx.gbl...
Hi all,

Does anyone know of a way to, programmatically with script at the server, reset the current user's security context from the IUSR_ account to a
different one? Ideally, what we'd do is anyone who is already logged in
as
a customer through our ASP page login (setting customer-specific session
variables), we'd programmatically impersonate them as a different windows account (switching them from the anonymous IIS account they start off as). Bottom line is that we don't want them to have to login a 2nd time to get to
these new pages.

We've got other non-asp files that I cannot simply put behind an ASP-based login, which is why we need to lock the directory down behind Windows
security.

Any thoughts would be appreciated! thanks,

Dan


Jul 22 '05 #3
"Dan" <da*********@hotmail.com> wrote in message
news:eL**************@TK2MSFTNGP14.phx.gbl...
thanks, exactly what I was looking for .. I thought I had exhausted the MS
knowledge base, but you've proven me wrong :-)


That will change the security context of the ASP page but I'm not sure it
will handle the non-asp files.

To protect the static files, place them outside of your root path and use an
ASP with ADODB.Stream and Response.BinaryWrite (or appropriate text file
methods) to serve the files to the user after they've passed your ASP
authentication scheme.

http://support.microsoft.com/support.../q276/4/88.asp

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsserv...y/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS
Jul 22 '05 #4

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

1
by: Graeme Coutts | last post by:
Developed a web application which adopts a custom security model which displays a login page and requests a username/password combination. The username works in a mixed-mode of usernames matched with...
1
by: win2kcowboy | last post by:
Using VS2003, ASP.NET 1.1 Is it possible to secure files normally placed as attachments (such as word docs etc.) and often placed in attachment directories within your web application, using...
7
by: David Brewster | last post by:
Hi everyone. I've been working with VB6 for a while now, I'm feeling pretty damn confortable with it, but find myself wondering about VB.NET and web applications. So I thought I'd get my feet wet....
2
by: Ian B | last post by:
This is a basic question for anyone who knows what they're doing with web server admin so hopefully someone will be able to assist me here!... I have a www based asp.net application which allows...
0
by: Jurjen de Groot | last post by:
I have build an ASP.NET application and would like to protect various folders containing aspnet pages for various usertypes. /Admin /Manager /User I've created a login on the default.aspx in...
1
by: Scott McChesney | last post by:
Folks - We are running around and around here on a project we're developing, and I'm getting to the point that I don't know what I do and don't know. So I need some assistance. We are...
5
by: Samba | last post by:
Hi, I've a web application and I'm using Forms authentication. My app contains some pages that can be viewed by everyone and it doesn't require any authentication or authoization and these pages...
2
by: Vaibhav Shah | last post by:
Hi, Can we secure HTML pages on a web site using asp.net? We have a requirement in which we want to display a login page before a visitor can view any HTML page on our website. WE have...
10
by: Les Desser | last post by:
In article <fcebdacd-2bd8-4d07-93a8-8b69d3452f3e@s50g2000hsb.googlegroups.com>, The Frog <Mr.Frog.to.you@googlemail.comMon, 14 Apr 2008 00:45:10 writes Thank you for that. It was very...
0
by: Charles Arthur | last post by:
How do i turn on java script on a villaon, callus and itel keypad mobile phone
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.