Ask a Question related to ASP.NET Security, Design and Development.
-
Gareth #1
Forms Authentication via SSL question
I have an ASP.NET application using forms authentication. I works without
any problems.
I have been trying to enable the login process to work over SSL but it fails
with the same problem everytime: "Access is denied". I have created my own
SSL certificate and enabled SSL encryption on a sub-directory of the web
site called "/IRWebAdmin/secure". In this directory is my "AdminLogin.aspx"
page.
In the root directory is my "AdminMain.aspx" page that is set as the
applications default page. On startup the application is directory to the
"/IRWebAdmin/AdminMain.aspx" page, which then is then referred to
"/IRWebAdmin/secure/AdminLogin.aspx" to login.
My web.config settings are:
<authentication mode="Forms" >
<forms loginUrl="https://localhost/IRWebAdmin/secure/AdminLogin.aspx"
requireSSL="true"
protection="All"
timeout="20"
name=".IRADM"
path="/secure"
slidingExpiration="true">
</forms>
</authentication>
<authorization>
<deny users="?" />
</authorization>
On running the application I get the standard security alert due to the
certificate not being from a trusted authority. Clicking YES then displays
this error page:
Server Error in '/IRWebAdmin' Application.
Access is denied.
Description: An error occurred while accessing the resources required to
serve this request. The server may not be configured for access to the
requested URL.
Error message 401.2.: You do not have permission to view this directory or
page using the credentials you supplied. Contact the Web server's
administrator for help.
Version Information: Microsoft .NET Framework Version:1.1.4322.573; ASP.NET
Version:1.1.4322.573
Does anyone have any information as to what I am doing wrong? I have trawled
the web for days now and nothing gives me the exact answer.
Regards,
Gareth.
Gareth Guest
-
Forms Authentication Question
Everything is working in my authentication process except for the fact that I can't retrieve the "UserData" property from the... -
Forms authentication then redirection to a secure web with NT authentication?
Hi, I want to allow access to particular secured intranet web sites. These intranet are stored in sharepoint (2003 version) Actually I've... -
asp.net FORMS authentication question
hi all with forms authentication, how does that work for a site with introduction and tour or maybe some more pages? by using forms... -
Basic Forms Authentication question
I can't get this damn thing to work at all. I have a virtual directory set up with anonymous access only, web.config contains the following but... -
Web Services and Forms Authentication Question
Hello, I'm a newbie in Web Services development. At present, we have a web site implement in ASP.NET with C#. We want to add some web service on... -
Paul Glavich [MVP - ASP.NET] #2
Re: Forms Authentication via SSL question
Have you tried installing your Certificate Authority as a trusted CA in the
"Trusted Root Ceritifcation Authorities" for your local machine (ie. both
server and client)?
--
- Paul Glavich
Microsoft MVP - ASP.NET
"Gareth" <gareth> wrote in message
news:OLr3dRDOEHA.2336@TK2MSFTNGP09.phx.gbl...fails> I have an ASP.NET application using forms authentication. I works without
> any problems.
>
> I have been trying to enable the login process to work over SSL but itown> with the same problem everytime: "Access is denied". I have created my"AdminLogin.aspx"> SSL certificate and enabled SSL encryption on a sub-directory of the web
> site called "/IRWebAdmin/secure". In this directory is myASP.NET> page.
>
> In the root directory is my "AdminMain.aspx" page that is set as the
> applications default page. On startup the application is directory to the
> "/IRWebAdmin/AdminMain.aspx" page, which then is then referred to
> "/IRWebAdmin/secure/AdminLogin.aspx" to login.
>
> My web.config settings are:
>
>
>
>
> <authentication mode="Forms" >
> <forms loginUrl="https://localhost/IRWebAdmin/secure/AdminLogin.aspx"
> requireSSL="true"
> protection="All"
> timeout="20"
> name=".IRADM"
> path="/secure"
> slidingExpiration="true">
> </forms>
> </authentication>
>
> <authorization>
> <deny users="?" />
> </authorization>
>
>
>
>
> On running the application I get the standard security alert due to the
> certificate not being from a trusted authority. Clicking YES then displays
> this error page:
>
>
>
> Server Error in '/IRWebAdmin' Application.
>
> Access is denied.
> Description: An error occurred while accessing the resources required to
> serve this request. The server may not be configured for access to the
> requested URL.
>
> Error message 401.2.: You do not have permission to view this directory or
> page using the credentials you supplied. Contact the Web server's
> administrator for help.
>
>
> Version Information: Microsoft .NET Framework Version:1.1.4322.573;trawled> Version:1.1.4322.573
>
>
>
>
> Does anyone have any information as to what I am doing wrong? I have> the web for days now and nothing gives me the exact answer.
>
> Regards,
> Gareth.
>
>
Paul Glavich [MVP - ASP.NET] Guest



Reply With Quote

