Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > Active Directory Authorization Store question

Reply
Thread Tools

Active Directory Authorization Store question

 
 
hey
Guest
Posts: n/a
 
      03-02-2005
I'm using Authorization and Profile block in my middle tier (.NET Remoting
hosted under IIS) for role-based application security. It's all good when the
authorization store is placed in a local xml file. But this is only good in
development. In production environment the store need to be integrated into
Active Directory.

The middle-tier (ASP.NET) is supposed to be configured to run under a least
privileged local account. But I cannot successfully configure any local
account (neither custom account nor built-in account) to communicate with the
remote AD authorization store.

The steps were:
1. Create an authorization store in AD
2. Assign the computer account of the server running ASP.NET to the Readers
group of the store.

My question is that whether a non-domain account can be used to run open and
query a remote authorization store in Active Directory. If yes then what is
the requirement for this local account (like membership, permissions etc)?

Thanks
Ming
 
Reply With Quote
 
 
 
 
Joe Kaplan \(MVP - ADSI\)
Guest
Posts: n/a
 
      03-02-2005
You'll need a domain account if you want to talk to AD using the credentials
of your current thread. If you can specify credentials somehow then you
have more flexibility.

Can you set up ASP.NET to run as a low privileged domain account?

Joe K.

"hey" <> wrote in message
news:82C6EA02-1DAB-4CD0-A355-...
> I'm using Authorization and Profile block in my middle tier (.NET Remoting
> hosted under IIS) for role-based application security. It's all good when
> the
> authorization store is placed in a local xml file. But this is only good
> in
> development. In production environment the store need to be integrated
> into
> Active Directory.
>
> The middle-tier (ASP.NET) is supposed to be configured to run under a
> least
> privileged local account. But I cannot successfully configure any local
> account (neither custom account nor built-in account) to communicate with
> the
> remote AD authorization store.
>
> The steps were:
> 1. Create an authorization store in AD
> 2. Assign the computer account of the server running ASP.NET to the
> Readers
> group of the store.
>
> My question is that whether a non-domain account can be used to run open
> and
> query a remote authorization store in Active Directory. If yes then what
> is
> the requirement for this local account (like membership, permissions etc)?
>
> Thanks
> Ming



 
Reply With Quote
 
 
 
 
hey
Guest
Posts: n/a
 
      03-02-2005
Thanks for your reply Joe.

For sure it works by using a domain account.

But the preference is to use a local account, which will be consistent to
the way to communicate with the backend sserver. We have set up mirrored
local account in the middle-tier and backend database server to facilitate
Windows authentication between the two.

Ming

"Joe Kaplan (MVP - ADSI)" wrote:

> You'll need a domain account if you want to talk to AD using the credentials
> of your current thread. If you can specify credentials somehow then you
> have more flexibility.
>
> Can you set up ASP.NET to run as a low privileged domain account?
>
> Joe K.
>
> "hey" <> wrote in message
> news:82C6EA02-1DAB-4CD0-A355-...
> > I'm using Authorization and Profile block in my middle tier (.NET Remoting
> > hosted under IIS) for role-based application security. It's all good when
> > the
> > authorization store is placed in a local xml file. But this is only good
> > in
> > development. In production environment the store need to be integrated
> > into
> > Active Directory.
> >
> > The middle-tier (ASP.NET) is supposed to be configured to run under a
> > least
> > privileged local account. But I cannot successfully configure any local
> > account (neither custom account nor built-in account) to communicate with
> > the
> > remote AD authorization store.
> >
> > The steps were:
> > 1. Create an authorization store in AD
> > 2. Assign the computer account of the server running ASP.NET to the
> > Readers
> > group of the store.
> >
> > My question is that whether a non-domain account can be used to run open
> > and
> > query a remote authorization store in Active Directory. If yes then what
> > is
> > the requirement for this local account (like membership, permissions etc)?
> >
> > Thanks
> > Ming

>
>
>

 
Reply With Quote
 
Joe Kaplan \(MVP - ADSI\)
Guest
Posts: n/a
 
      03-03-2005
I'm not a huge fan of the mirrored local account as it is pretty brittle.
Wouldn't it be easier to use a domain account for that purpose too? That
would seem to solve both problems. You can still use a least privilege
account for this purpose.

Joe K.

"hey" <> wrote in message
news:B288627D-BB4B-4E68-B5B2-...
> Thanks for your reply Joe.
>
> For sure it works by using a domain account.
>
> But the preference is to use a local account, which will be consistent to
> the way to communicate with the backend sserver. We have set up mirrored
> local account in the middle-tier and backend database server to facilitate
> Windows authentication between the two.
>
> Ming
>
> "Joe Kaplan (MVP - ADSI)" wrote:
>
>> You'll need a domain account if you want to talk to AD using the
>> credentials
>> of your current thread. If you can specify credentials somehow then you
>> have more flexibility.
>>
>> Can you set up ASP.NET to run as a low privileged domain account?
>>
>> Joe K.
>>
>> "hey" <> wrote in message
>> news:82C6EA02-1DAB-4CD0-A355-...
>> > I'm using Authorization and Profile block in my middle tier (.NET
>> > Remoting
>> > hosted under IIS) for role-based application security. It's all good
>> > when
>> > the
>> > authorization store is placed in a local xml file. But this is only
>> > good
>> > in
>> > development. In production environment the store need to be integrated
>> > into
>> > Active Directory.
>> >
>> > The middle-tier (ASP.NET) is supposed to be configured to run under a
>> > least
>> > privileged local account. But I cannot successfully configure any local
>> > account (neither custom account nor built-in account) to communicate
>> > with
>> > the
>> > remote AD authorization store.
>> >
>> > The steps were:
>> > 1. Create an authorization store in AD
>> > 2. Assign the computer account of the server running ASP.NET to the
>> > Readers
>> > group of the store.
>> >
>> > My question is that whether a non-domain account can be used to run
>> > open
>> > and
>> > query a remote authorization store in Active Directory. If yes then
>> > what
>> > is
>> > the requirement for this local account (like membership, permissions
>> > etc)?
>> >
>> > Thanks
>> > Ming

>>
>>
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
System.IO.Directory.GetDirectories() and System.IO.Directory.GetFiles() are not returning the specified directory Nathan Sokalski ASP .Net 2 09-06-2007 03:58 PM
URL Authorization does not override File Authorization? SeanRW ASP .Net Security 1 05-25-2006 06:18 AM
Excluding page authorization in a form authentication directory Gnic ASP .Net 2 03-21-2006 04:00 PM
Authorization against Active Directory Miika Parvio Java 0 01-14-2005 08:06 AM
Active Directory Search fails ("The directory service is unavailab ejcosta ASP .Net Security 2 10-08-2004 09:57 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57