IIS Server Security - Re: IIS authentication - Update 2

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > February 2004 > Re: IIS authentication - Update 2





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Re: IIS authentication - Update 2
Blake

2004-02-26, 10:34 am

Now the 'change password' seems to work:

The server was unable to logon the Windows NT account 'testbb' due to the
following error: The user's password must be changed before logging on the
first time.

I guess I should have waited longer when I disabled the IDs.

Blake

"Blake" <blake_duffey@NOSPAM.hotmail.com> wrote in message
news:ONbaQiH$DHA.2316@tk2msftngp13.phx.gbl...
> OK - I have IIS 5 on a member server. The files are set at the NTFS level
> to 'authenticated users' (RX) and the IIS folder is set to 'basic
> authentication' ONLY. I have SSL required for this folder. I am trying

to
> allow only valid AD users to visit this page:
>
> 1) can a user whose account is DISABLED view this page? I thought no, but
> today it seems to work
> 2) in the past an account that was marked 'user must change password at

next
> logon' could NOT access this page, but now that seems to work too
> 3) if an account has it's password expire, can that account visit my web
> page?
>
> Does anyone have any references on the connection between AD IDs and IIS
> authentication?
>
> Thanks, as always
> Blake
>
>



Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com