13.07.2015 Views

EPiServer Operator's Guide - EPiServer World

EPiServer Operator's Guide - EPiServer World

EPiServer Operator's Guide - EPiServer World

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4 | <strong>EPiServer</strong> <strong>Operator's</strong> <strong>Guide</strong>/Web.Config Read/write Used to be able to savesystem settings.Internet Information Server (IIS)AuthenticationThe authentication mechanism you choose in IIS depends on the authentication you use in ASP.NET. If you useforms authentication, as we recommend, you should only allow Anonymous access, as IIS is not responsible forauthentication then.If you use Windows authentication in ASP.NET, you should configure IIS for Basic Authentication or IntegratedAuthentication. Integrated Authentication cannot normally be used over firewalls, which is why it is normally onlyan alternative for intranets.Refer to the white paper, "Security in <strong>EPiServer</strong>" for a more detailed description, including the advantages anddisadvantages of using certain authentication mechanisms.Directory Settings<strong>EPiServer</strong> 4 is a pure ASP.NET application and does not require any settings other than the standard settings. Itis, however, advisable to secure directories so that certain file types are not allowed in certain directories. Theground rule is to only allow Read permission in directories with downloadable files, like images, and only Scriptpermission in directories with script files, e.g. ASP.NET files. This is so that the code can only be executed andnot read. An exception is that IIS 5.0 requires Read permission to be set on a directory in order for a defaultdocument to work, e.g. default.aspx. This mainly applies to the admin, edit and root directories.Our recommendations for directory settings can be found in the table below:Directory Read Write Log accessDirectorybrowsingallowedIndex thisdirectoryPermissions/ X X X ScriptAdmin X X Scriptadmin/Download X NoneEdit X X ScriptHelp X X NoneImages X X NoneLang X NoneStyles X X NoneUtil X ScriptUtil/activex X X NoneUtil/flash X X NoneUtil/help X X NoneUtil/images X X NoneUtil/javascript X X NoneCopyright © ElektroPost Stockholm AB - www.episerver.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!