Click here to get back home

Win 2003 server port for authorized users

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Win 2003 server port for authorized users lolek1021 01-10-2006
Posted by lolek1021 on January 10, 2006, 11:54 am
Please log in for more thread options
Hi,
I have a server application working on a Windows 2003 Server (or
Windows 2000 Server). This server application has got CORBA API. On the
same machine CORBA Name Server is installed.
Every client application first connects to the COBBA Name Server, gets
information about server application (IP, port number). Having this
information it connects to the server application on a known port
(always the same).
Has Windows 2003 server such posibility to let to connect to a specific
port number only authorized users? For example if client application
tries to connet to server on port number equal 123457 then server as it
for login and password (for example domain login and password) .
Is this or any similar in effect solution possible?
Thx for any ideas:)
Lolek1021


Posted by Ondrej Sevecek on January 11, 2006, 5:58 am
Please log in for more thread options
yes, some kind of only. You can implement IPSec that would authenticate
client *computers* against certificate issued by some specific CA. nothing
other is possible. If you want and authentication, you will have to install
some firewall (for example ISA SErver) and provide client computers with
some firewall client software (also available with ISA Server).


O.




> Hi,
> I have a server application working on a Windows 2003 Server (or
> Windows 2000 Server). This server application has got CORBA API. On the
> same machine CORBA Name Server is installed.
> Every client application first connects to the COBBA Name Server, gets
> information about server application (IP, port number). Having this
> information it connects to the server application on a known port
> (always the same).
> Has Windows 2003 server such posibility to let to connect to a specific
> port number only authorized users? For example if client application
> tries to connet to server on port number equal 123457 then server as it
> for login and password (for example domain login and password) .
> Is this or any similar in effect solution possible?
> Thx for any ideas:)
> Lolek1021
>



Posted by Roger Abell [MVP] on January 12, 2006, 4:01 am
Please log in for more thread options
OK, let us dissect this a little.

The CORBA name server is just providing contact info.
The client uses that and gets challenged _by_the_application_
at the contact point (key point - it is not challenged by the machine)
but by the CORBA application.

Windows does similarly.
Clients quiry DNS for SRV records, or query AD for SPN of service.
This contact info is then used to attempt to access the service. The
service then, being a proper Kerberos application, triggers the normal
Kerberos ticket process to see if the client is allowed access to the
service.

Windows is coming to do this now more in the WS* based web services
pattern for many things moving forward.


> Hi,
> I have a server application working on a Windows 2003 Server (or
> Windows 2000 Server). This server application has got CORBA API. On the
> same machine CORBA Name Server is installed.
> Every client application first connects to the COBBA Name Server, gets
> information about server application (IP, port number). Having this
> information it connects to the server application on a known port
> (always the same).
> Has Windows 2003 server such posibility to let to connect to a specific
> port number only authorized users? For example if client application
> tries to connet to server on port number equal 123457 then server as it
> for login and password (for example domain login and password) .
> Is this or any similar in effect solution possible?
> Thx for any ideas:)
> Lolek1021
>



Similar ThreadsPosted
IAS authenticating users in trusted domain (server 2003 ent.) October 20, 2005, 1:04 pm
Possible compromise of Windows Server 2003 security risk & unknown users December 7, 2005, 11:29 am
Windows 2003 Domain Controller (Open Port 593) December 18, 2006, 4:48 pm
DHCP Server Changes Source Port In Middle of Connection March 29, 2008, 9:45 pm
W2K netstat detects port 1433 is listenning but fport does NOT..., can't start mission critical sql server !!! October 14, 2005, 1:20 pm
Users tab in Task Manager on Windows 2003 November 10, 2005, 12:28 pm
Users browsing network via Office 2003 October 7, 2006, 7:49 am
Windows 2003 R2 delegated permissions are not available for some users in an OU January 2, 2007, 12:15 pm
Power Users & Servers - Windows 2000 & 2003 Differences December 7, 2006, 9:32 am
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap