16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 15: Configuring Windows SharePoint Services 377<br />

■ Integrated Windows authentication. Integrated Windows authentication<br />

(also known as Windows NT Challenge Response) encrypts user names <strong>and</strong><br />

passwords in a multiple-transaction interaction between client <strong>and</strong> server, thus<br />

making this method more secure than Basic authentication. Disadvantages are<br />

that this method cannot be performed through a proxy server firewall, <strong>and</strong><br />

some Web browsers (most notably, Netscape Navigator) do not support it. You<br />

can, however, enable both this method <strong>and</strong> Basic authentication at the same<br />

time, <strong>and</strong> most Web browsers will select the most secure option. (For example,<br />

if both Basic <strong>and</strong> Integrated Windows authentication are enabled, <strong>Microsoft</strong><br />

Internet Explorer will try Integrated Windows authentication first.)<br />

■ Certificates authentication. Certificates authentication provides communications<br />

privacy, authentication, <strong>and</strong> message integrity for a TCP/IP connection.<br />

By using the SSL protocol, clients <strong>and</strong> servers can communicate in a way that<br />

prevents eavesdropping, tampering, or message forgery. With Windows Share-<br />

Point Services, SSL helps secure authoring across firewalls <strong>and</strong> allows more<br />

secure remote administration of Windows SharePoint Services. You can also<br />

specify that SSL be used when opening any website based on Windows Share-<br />

Point Services.<br />

You can change authentication methods for virtual servers hosting websites<br />

based on Windows SharePoint Services, <strong>and</strong> you can change the authentication<br />

method used for the SharePoint Central Administration site. You can also enable<br />

Secure Sockets Layer (SSL) security in IIS to help protect your sites or the administration<br />

port for your server.<br />

Caution It should be strongly noted that enabling SSL after establishing the<br />

Windows SharePoint Services site is very difficult. The reason is that Windows<br />

SharePoint Services in some cases uses the https:// protocol behind<br />

the scenes when interfacing with the database. This then makes changing<br />

the URL after the fact a difficult task.<br />

Changing Authentication Methods<br />

Each virtual server can use a different authentication method in Internet Information<br />

Services (IIS). You can even enable multiple authentication methods if you are using<br />

the same website content in more than one environment. For example, if you have a<br />

website that is primarily for internal use within your organization, you would most<br />

likely choose Integrated Windows authentication. (It should be noted here that Internet<br />

Explorer must be your organization’s st<strong>and</strong>ard browser.) If, however, your use of<br />

the site changes <strong>and</strong> you must allow your organization’s members to access the site<br />

externally through a firewall, you might also want to enable Basic authentication.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!