Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsFree MagazinesWhite PapersSubmit Content
Discussion GroupsASP.NETWindows FormsLanguages.NET FrameworkVisual Studio.NET
Articles.NET FrameworkASP.NETToolsWindows Forms
.NET DirectoryOpen Source ProjectsUser GroupsWeb Resources
Related Topics
Visual Basic 6SQL ServerMS AccessOther DB ProductsMS Server ProductsMore Topics ...

.NET Forum / .NET Framework / Security / May 2005

Tip: Looking for answers? Try searching our database.

.Net Authorization and NTFS permissions

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Wade Mebed - 27 May 2005 17:57 GMT
We get inconsistent application behavior on Authorization based on NTFS ACL
Permissions.

We implemented an ASP.NET 1.1 web application using NTFS ACL Authorization,
and implemented a security audit logging call in the
Application_AuthorizeRequest event of the Global.asax:
    protected void Application_AuthorizeRequest(Object sender, EventArgs e)
        {
            AuditLog.LogAccessAttempt();
        }

The audit logging is designed to log access attempts - both authorized and
unauthorized.  For the web application we use integrated windows
authentication (this is an intranet application). On the web application
directory NTFS permissions, we add the roles which are authorized to the
application.  In the web.config we configure the authentication and
authorization as follows:

 <authentication mode="Windows" />

 <authorization>
   <allow users="*" />
 </authorization>

On the development servers upon which we intitially tested the
unauthenticated users received 403 HTTP response codes, and their access was
logged by our audit logging mechanism (the call embedded in the
Application_AuthorizeRequest).

Then we found that on the QA servers, although the unauthenticated users
received a 401.3 HTTP response code, the audit logging for unauthorized
access was not executed.  Debugging showed that IIS never passed control to
the Application_AuthorizeRequest event. The requests of users who are not
authorized via NTFS ACL's (yet are authenticated) do not get to the
Application_AuthorizeRequest event.

We checked that IIS and the NTFS ACL's were configured the same on all
machines, and that they all ran the same OS and IIS versions: Windows Server
2000 SP4 and IIS 5.00.

NTFS ACL's included group that needed access with read, read & execute, and
list file contents.

Why do we see this inconsistent behavior?
Yunus Emre ALPÖZEN [MCSD.NET] - 29 May 2005 18:44 GMT
If i clearly understand what u mean, u would like to log requests. And you
want be aware of if user is authenticated or not ?

My advice u, to handle Application AuthenticateRequest event. Because of
using Windows authentication, the request authentication is done
automatically. You should handle authentication attempy at
AuthenticateRequest stage. At this stage User property is set to null. After
this stage, user property is set. U can log client ip or any relevant
information at this stage without using user property.....

Hope i cleary understood what u mean and what u need....

Signature

Thanks,
Yunus Emre ALPÖZEN
BSc, MCSD.NET

> We get inconsistent application behavior on Authorization based on NTFS
> ACL
[quoted text clipped - 46 lines]
>
> Why do we see this inconsistent behavior?

Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.