SSL and Forms Authentication

S

Scott

Hi,

I've seen this problem posted a few times around the 'net with no answer.
Hopefully someone here can help.

We have our website configured to use Forms Authentication. We want to
secure the Login page ONLY using SSL. When a user goes to the site he is
redirected to the Login page for authentication, but gets an error saying
the resource is protected and they must use HTTPS:.

That's ugly, since the redirect should be transparent to the user.

When we setup the <forms> tag we have tried using the full path in the
loginUrl property, including 'httpS://'. When we do this the user doesn't
get the message about HTTPS, but he DOES get an NT Authentication login
dialog instead.

Thats even uglier and I'm not even sure why that happens.

Documentation and books I've read allude to the abiltiy to secure a single
folder or page using SSL and the login redirection works. Those same
documents and books don't say HOW to make it work and we haven't been able
to either.

Is it even possible to do this? Has anyone here done it successfully?

Scott L.
 
P

Paul Glavich

Perhaps you could try and put some code in the Application_Authenticate
event that checks to see if the user is already authenticated, if not, then
issue a manual redirect to your HTTPS login page.
 
J

Justin

I've been trying to figure this out too, without luck. I just work around it
by
redirecting to a relative aspx page from the loginurl in web.config, then
do a response.redirect(https://www.host.com/login.aspx) from that. Messy
but it works

Justin
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

Forum statistics

Threads
473,989
Messages
2,570,207
Members
46,783
Latest member
RickeyDort

Latest Threads

Top