Forms Authentication - Single Sign-On

Discussion in 'ASP .Net Security' started by jct, Jan 18, 2005.

  1. jct

    jct Guest

    I am implementing a single sign-on system in ASP.Net. The technique I am
    using is as defined by Paul Sheriff, in the MSDN article Single Sign-On
    Enterprise Security for Web Applications.

    http://msdn.microsoft.com/asp.net/u...l=/library/en-us/dnaspp/html/singlesignon.asp

    I am running into a problem with the Forms Authentication on the internal
    web site side. The article provides for the Internal Website (i.e. that one
    called by a launcher app) to be secured using Forms Authentication, where
    internal users connect to an AppLogin.aspx page, passing a security token,
    generated by a launching application. The token is checked on the
    AppLogin.aspx Page_Load.

    My problem is I never get to the AppLogin.aspx Page_Load because I have not
    authenticated. Instead I get to Login.aspx which is the loginUrl defined in
    my Webconfig...

    <authentication mode="Forms">
    <forms name="SignOnTest" loginUrl="Login.aspx" />
    </authentication>

    The download sample for the article does not work properly as the webconfig
    there has...

    <authorization>
    <allow users="*" />
    </authorization>

    which I believe negates the Forms Authentication.

    My webconfig has this...

    <authorization>
    <deny users="?" />
    </authorization>


    If I change that the download behaves as my code does, and never gets to the
    page that checks the security token passed by the launching app.

    Does anybody have any ideas; I must be missing something obvious.

    Much appreciated,

    Justin
     
    jct, Jan 18, 2005
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. LouB
    Replies:
    0
    Views:
    333
  2. Gabriel Giraldo

    Single Sign-On with Forms Authentication

    Gabriel Giraldo, May 25, 2005, in forum: ASP .Net Security
    Replies:
    2
    Views:
    132
    Gabriel Giraldo
    May 26, 2005
  3. Dave Slinn

    Transfer authentication token - how to single sign-on

    Dave Slinn, Nov 13, 2005, in forum: ASP .Net Security
    Replies:
    10
    Views:
    544
    [MSFT]
    Nov 23, 2005
  4. SP
    Replies:
    7
    Views:
    241
    Joe Kaplan
    Feb 14, 2007
  5. bthumber

    CAC authentication Single Sign-on

    bthumber, Apr 23, 2009, in forum: ASP .Net Security
    Replies:
    2
    Views:
    769
    bthumber
    Apr 24, 2009
Loading...

Share This Page