11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

560 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>AuthenticationThe element configures the authentication mode that yourapplications use.The appropriate authentication mode depends on how your application or <strong>Web</strong>service has been designed. The default Machine.config setting applies a secureWindows authentication default as shown below.Forms Authentication GuidelinesTo use Forms authentication, set mode=“Forms” on the element.Next, configure Forms authentication using the child element. Thefollowing fragment shows a secure authentication element configuration: Sliding session lifetimeUse the following recommendations to improve Forms authentication security:●●●●●●●●●Partition your <strong>Web</strong> site.Set protection=“All”.Use small cookie time-out values.Consider using a fixed expiration period.Use SSL with Forms authentication.If you do not use SSL, set slidingExpiration = “false”.Do not use the element on production servers.Configure the element.Use unique cookie names <strong>and</strong> paths.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!