Authentication


Check

Description

Anonymous authentication is disabled in IIS.

ASP.NET is configured for Windows authentication.

Client credentials are configured at the client through the proxy object.

Authentication connection sharing is used to improve performance.

Clients are forced to authenticate on each call ( unsafeAuthenticatedConnectionSharing is set to "false").

connectionGroupName is specified to prevent unwanted reuse of authentication connections.

Plain text credentials are not passed over the network.

IPrincipal objects passed from the client are not trusted.




Improving Web Application Security. Threats and Countermeasures
Improving Web Application Security: Threats and Countermeasures
ISBN: 0735618429
EAN: 2147483647
Year: 2003
Pages: 613

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net