Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsFree MagazinesWhite PapersSubmit Content
Discussion GroupsASP.NETWindows FormsLanguages.NET FrameworkVisual Studio.NET
Articles.NET FrameworkASP.NETToolsWindows Forms
.NET DirectoryOpen Source ProjectsUser GroupsWeb Resources
Related Topics
Visual Basic 6SQL ServerMS AccessOther DB ProductsMS Server ProductsMore Topics ...

.NET Forum / Windows Forms / WinForm General / June 2006

Tip: Looking for answers? Try searching our database.

ClickOnce deployment security on the Internet

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Thirsty Traveler - 12 Jun 2006 17:37 GMT
We have a TabletPC application used by remote, roaming users who only have
Internet access. We would like to place the deployment site on our Internet
so they will be able to apply updates, however the issue of security for
ClickOnce seems not to have been considered by Microsoft for some odd reason
(considering that Microsoft has, in theory, become so security conscience
these days). For example, we would like the users to be authenticated prior
to applying updates. This can be somewhat dicey because we do not have AD
for our internal network users in the DMZ, even if it could be done at all
(which appears to not be the case).

Has anyone faced this issue and, if so, how did you go about solving it?
Robbe Morris [C# MVP] - 13 Jun 2006 01:03 GMT
Nope, we use AD to enforce this stuff.  That said,
if you open up the default.htm generated by
clickonce, you'll see it ain't doing a whole lot.

You could easily do away with default.htm
and replace it with a .asp or .aspx page
that incorporates your own authentication.

You'd have to tweak stuff to hide the folders and
files.  But, it could definitely be done.

P.S.  I think MS is really heavily on AD if
you want something like this locked down.

You could also make the site only accessible
from inside your network.

Signature

Robbe Morris - 2004-2006 Microsoft MVP C#
Earn money answering .NET questions
http://www.eggheadcafe.com/forums/merit.asp

> We have a TabletPC application used by remote, roaming users who only have
> Internet access. We would like to place the deployment site on our
[quoted text clipped - 7 lines]
>
> Has anyone faced this issue and, if so, how did you go about solving it?
Thirsty Traveler - 13 Jun 2006 16:13 GMT
I would prefer to limit it to the inside network, but unfortunetly our
TabletPC's are being used by remote staff throughout the country. For SOX
reasons, we are not allowed to give them VPN access to our internal network.

> Nope, we use AD to enforce this stuff.  That said,
> if you open up the default.htm generated by
[quoted text clipped - 24 lines]
>>
>> Has anyone faced this issue and, if so, how did you go about solving it?
Andy - 14 Jun 2006 19:34 GMT
> I would prefer to limit it to the inside network, but unfortunetly our
> TabletPC's are being used by remote staff throughout the country. For SOX
> reasons, we are not allowed to give them VPN access to our internal network.

I have to ask; what specifically in SOX disallows you from giving VPN
access to your internal network?  It would seem rather odd that SOX
suddenly makes the use of VPN illegal...
Thirsty Traveler - 15 Jun 2006 20:18 GMT
It is not illegal, but VPN access is tightly controlled and much more
difficult to get approval.

>> I would prefer to limit it to the inside network, but unfortunetly our
>> TabletPC's are being used by remote staff throughout the country. For SOX
[quoted text clipped - 4 lines]
> access to your internal network?  It would seem rather odd that SOX
> suddenly makes the use of VPN illegal...

Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.