IIS Server Security - WebDAV and basic authentication

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > June 2005 > WebDAV and basic authentication





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author WebDAV and basic authentication
Stefano

2005-06-09, 7:49 am

Hi all,

this is the environment:
Windows Server 2003 (no SP1), and so IIS 6
Windows XP Pro SP1 and IE 6

I created a new Virtual Web Site in IIS, using a new "host header name":
testprojectsvr.
I allowed Read/Write/DirBrowsing permissions of the entire web site (for
testing purpose only), and enabled ONLY Basic authentication for the site
(so anonymous access is disabled).
I enabled WebDAV on "Web Server Extensions" of IIS.

This is the tree of the web site:
/root
/myvirtualdir
/mydir
myfile.txt

My goal is to connect to "http://testprojectsvr/myvirtualdir" web folder
(So using WebDAV) from the Windows XP client, for reading and writing file
on the server.

When I try to connect to the web folder using IE (File->Open...-> "open as
web folder" check), I'm continously prompted for the user credentials (I
use administrator credential... bot using the form "servername\administrator"
and "administrator" for the username field).

If I change the authentication mode to "Windows Integrated" everything is
OK (because in this case I'm authenticated as a domain user that is also
a local administrator for the server).

I know that this was a bug in IIS 5:
http://support.microsoft.com/defaul...kb;en-us;315621

What about IIS 6 and IE 6?
Are there some fix?!?

Thank you so much.

Bye


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com