Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Wednesday, March 7, 2012

Different SQL Server Users on ASP.Net

Hi there,

When conecting to a MS SQL Server 2005, I could define in my connection string Windows Authentication.

What account it will be used? The one used by IIS (I still don't know the user ASP.net runs, if it is independent of IIS or not)?

And if I whant that some aspx pages have diferente acess rights? I need to use SQL Server Authentication with diferent users created in MS SQL Server right?

In ASP.net, what is best practice: Have one SQL account, and make users access rights in Business Logic, or have different SQL Accounts por the diferent access rights I whant in every page?

Sorry if this are basic questions, but In the find's I made, I saw very confusion ideas.

Thanks in advance, and sorry my english.

Alberto Ferreira

Hi Alberto,

ASP.NET runs under the ASPNET account (you can check under users to get more info about this account)

Unlike Client Server application. You dont have to follow the same logic in Web application.

You have to implement a Forms Authentication for authentication and implement GenericPrincipal containing IPrincipal and IIdentity for authorization.

In that you would create your Custom Screen Permission or Screen-Screen Action permission lookup table. You would find plenty of articles on this.

For connection pooling to take place the connection string has to be the same so in ASP.NET we reuse the same user name and password but we control the security at the application level than the database level which we previously used to do.

And never mind the englishSmile

Happy Programming

Anton

Saturday, February 25, 2012

Different Performance on different XMLA Authentications

Hi,

I am using XMLA to connect to SSAS2005. By using different authentication methods in virtual directory, It returns the same result but different speed.

When I using Anonymous Account IUSR_MachineName, the query will return in 1 seconds. But if i using Integrated Windows Authentication, the query will take approximately 5 seconds to return the result. Any Idea?

I have using SQl server Profiler to trace the step. both of it using same number of steps. The different is if using anonymous, then some of the step is return 0 in duration columns. While if using windows authentication, it will longer. But the result of the step is the same.

So, Any Idea? Or does anyone face it before? Thanks.

The difference is most likely caused by the amount of time that it takes the IIS/SSAS server(s) to talk to the domain controller to check the credentials of the user. With anonymous, it is using a fixed local account for which it does not have to do this. Do you have anyone that could help you check the domain side of things?