IUSR_COMPUTERNAME vs ASPNET

Ask a Question related to ASP.NET Security, Design and Development.

  1. #1

    Default IUSR_COMPUTERNAME vs ASPNET

    Hello people.Sorry for stupid question.But who can exlplain to me difference
    between IUSR_COMPUTERNAME and ASPNET account.


    Anatolij Guest

  2. Similar Questions and Discussions

    1. User ASPNET
      I have a share in other computer and I want access to that sahre with my web application. For that I do: - Create a User ASPNET in my domain - Use...
    2. Restricting ASPNET ACLs without breaking ASPNET (newbie-ish)
      Scenario: We have a library with objects that host Jscript for the execution of complex validation code. This library is being called by an ASP.NET...
    3. ASPNET and Impersonation
      Maybe someone the aspnet.security group has some other suggestions. Shel -- This posting is provided "AS IS" with no warranties, and confers...
    4. ASPNET user.
      When I install Visual Studio, VSDEBBUGERS and VSDEVELOPERS groups are created. Right? What about the ASPNET user? Do I have to create it manually? ...
    5. ASPNET: VS CF
      We were using ColdFusion for our Intranet in the past. We just moved to ASP.Net for our new development. In my opinion, ASP.Net is much more...
  3. #2

    Default Re: IUSR_COMPUTERNAME vs ASPNET

    The first one is an IIS account used for the anonymous authentication, the
    second one is an ASP.NET account used for the asp.net worker process.

    HtH,
    Andrea

    --
    This posting is provided "AS IS" with no warranties, and confers no rights.

    "Anatolij" <lankas73@hotmail.com> wrote in message
    news:%23Tfo9JzPEHA.2876@TK2MSFTNGP09.phx.gbl...
    > Hello people.Sorry for stupid question.But who can exlplain to me
    difference
    > between IUSR_COMPUTERNAME and ASPNET account.
    >
    >

    Andrea D'Onofrio [MSFT] Guest

  4. #3

    Default Re: IUSR_COMPUTERNAME vs ASPNET

    ASP.NET takes advantage of two layers of security: 1) IIS Security, 2)
    ASP.NET Security

    You may read about the security model here:
    [url]http://aspnet.4guysfromrolla.com/articles/031204-1.aspx[/url]

    What happens is that first, IIS has to authenticate the user. IIS may be set
    to one of several different authentication modes, of which one is
    "Anonymous". In old ASP, if you selected this option only, the user would
    not be authenticated. All the actions of the user would be done using the
    "IUSR_MACHINENAME" account.

    In ASP.NET you may still be using the same account if you 1) set
    authentication in IIS to use Anonymous, and 2) set the
    <impersonation="true"> in web.config.

    The default, however is <impersonation="false"> which means the "ASPNET"
    user account will be used.

    If you want to use integrated windows authentication (acces to the website
    is done under the users domain or local windows account), then you should
    select "Windows Authentication" in IIS and <authentication mode="windows">
    (default setting) in web.config. And you should set <impersonation="true">.

    Sincerely
    Svein Terje Gaup


    Svein Terje Gaup Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139