Có Không Không Không Có N / A - Những tập tin này không được xử lý bằng ASP NET. Với bất kỳ cơ chế (không phải dấu mặt) xác thực IIS, các điều khoản phải được cấu hình cho người dùng cá nhân xác thực. Với xác thực dấu mặt, các điều khoản cần phải được cấu hình cho IUSR_MACHINE. không có | 142 Building Secure Applications Table Windows authentication and impersonation requirements Authorization Option Requires Windows Authentication Requires Impersonation FileAuthorizationModule Yes No UrlAuthorizationModule No No Principal Permission Demands No No .NET Roles No No Enterprise Services Roles application Yes Yes within the ASPNET Web NTFS Permissions for directly requested static files types not mapped to an ISAPI extension N A - These files are not handled by ASPNET. With any non-Anonymous IIS authentication mechanism permissions should be configured for individual authenticated users. With Anonymous authentication permissions should be configured for iusr_mAchine. No IIS performs the access check. NTFS Permissions for files accessed by Web application code No No If impersonating configure ACLs against the impersonated Windows identity which is either the original caller or the identity specified on the identity element in . The impersonated identity may be the original caller or the identity specified on the identity element in . Consider the following two identity elements. identity impersonate true identity impersonate true userName Bob password pwd The first configuration results in the impersonation of the original caller as authenticated by IIS while the second results in the identity Bob. The second configuration is not recommended for two reasons It requires that you grant the process identity the Act as part of the operating system privilege on the Microsoft Windows 2000 operating system. It also requires you to include a plain text password in . Both of these restrictions will be lifted in the next release of the .NET Framework. Chapter 8 Security 143 Windows Authentication with Impersonation The following configuration elements show you how to enable Windows IIS authentication and impersonation declaratively in or . Note You should configure authentication .