Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 27, 2000

Internet Information Services 5.0 Authentication Methods


RSS
Subscribe to Windows IT Pro | See More Windows 2000 Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Microsoft includes Internet Information Services (IIS) 5.0 with both Windows 2000 Server (Win2K Server) and Windows 2000 Professional (Win2K Pro). However, by default, IIS installs only on Win2K Server, not on Win2K Pro. But if you upgrade to Win2K Pro from an earlier version of Windows, IIS will install. To configure IIS properly, you must understand the various authentication methods that the software uses. You can set authentication, the process whereby the client identifies itself to the IIS server, at the Web site level, at the folder level, or at the file level. IIS 5.0 offers five authentication methods for the Web:

  • Anonymous
  • Basic
  • Digest
  • Integrated Windows
  • Certificate

Two IIS 5.0 authentication methods apply to FTP:

  • Anonymous FTP
  • Basic FTP

Anonymous Authentication
If you don’t want IIS to prompt users for a username and password, you can set Anonymous authentication on your Web server, and IIS will assign users to an account that belongs to the Guests group. The default account—IUSR_computername, where computername is the name of your IIS server—is the account we typically refer to when we talk about anonymous accounts in IIS. The IUSR_computername account must have log on locally user rights on the server or users won't be able to connect to your Web server. You can restrict anonymous user access to your server using file- or folder-level NTFS permissions. IIS tries Anonymous authentication first but will try a different authentication method if access is restricted. If no other method is available, IIS sends the user an "HTTP 403 Access Denied" error message.

Basic Authentication
To comply with HTTP specifications, most browsers support Basic authentication. IIS prompts users for a valid Windows account and password. However, because the password transmits unencrypted, most people avoid using Basic authentication in secure environments. As a workaround, you can use Secure Socket Layer (SSL) with Basic authentication so that the password isn't vulnerable.

Digest Authentication
Digest authentication, a new feature in IIS 5.0, is similar to Basic authentication except that the authentication credentials passed through a hashing algorithm. The resulting hash, or message digest, is encrypted, so it's more secure than the clear-text passwords that Basic authentication uses. The Digest authentication method works across proxy servers and firewalls. However, only browsers that support HTTP 1.1 can take advantage of this authentication; IIS 5.0 denies access to non-compliant browsers.

Integrated Windows Authentication
Previously known as Windows NT Challenge/Response (NT/CR) or NT LAN Manager (NTLM), Integrated Windows authentication is a secure authentication method that doesn’t transmit usernames or passwords. Instead, it relies on a cryptographic exchange with the server. Integrated Windows authentication can use either the Kerberos 5 authentication protocol or its own challenge/response protocol.

If you have already logged on to Windows, Integrated Windows authentication uses your logon information to authenticate you, so it won’t prompt you for a username and password. If you haven’t already logged on to Windows, Integrated Windows authentication continues to prompt you for a valid username and password until you either supply the proper information or close the dialog box. The disadvantage of Integrated Windows authentication is that it works only with IE 2.0 or later. Netscape Navigator and other browsers don’t support this authentication method. Also, Integrated Windows authentication doesn’t work with HTTP proxy. Ideally, you want to use this authentication method in an intranet environment, where you can control the types of browsers that your network users use.

Certificate Authentication
You can use server and client certificates to authenticate users on your Web site before they transmit confidential information. You can map a client certificate to a Windows user account so that the user can log on automatically, without supplying a username and password. You can map either one client certificate to one Windows account, or many certificates to one account.

Anonymous FTP Authentication
The Anonymous FTP authentication concept is identical to that of Anonymous authentication for the Web. Users can connect to your FTP server without providing usernames and passwords because IIS uses IUSR_computername to provide anonymous access. You can always specify a different account for anonymous access. You can also restrict access to resources using NTFS permissions. Note that even if you enable Basic authentication, Anonymous authentication always takes precedence, and IIS will use it first.

Basic FTP Authentication
The Basic FTP authentication concept is identical to that of Basic authentication for the Web. Basic FTP authentication prompts FTP users for a username and password, which transmit in clear text. Some administrators force users to use Anonymous FTP authentication because it doesn't prompt users for passwords and doesn't, therefore, expose domain passwords to others. The administrators control user access through NTFS permissions.

Table 1 shows a summary of IIS 5.0 authentication methods.

End of Article



Reader Comments
How do you know you are authenticated via kerberos in iis. The authentication type is Negotiate, but that could be either kerberos or NTLM, is there a way to tell withing an asp.net page?

Harrison Davis October 18, 2002


The article is really good. Explains in minutes details the authetication nethods. Thanks

Anonymous User February 01, 2005 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

The Desktop tab is missing from the Display Properties in Windows XP?

...


IIS and Web Administration Whitepapers The Five Secrets to Controlling Your SharePoint Environment

Extended Validation SSL Certificates

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Related IIS and Web Administration Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing