4.2 Authorization - 'allow users'

Information

If authorization is determined, the user will be automatically redirected to a page where they must submit their credentials. NOTE: This check audits the default system drive. If your organization's configuration is different the '%systemdrive%' variable will need to be adjusted. NOTE2: Change <framework_version> to the version of .NET that is in use by your organization. NOTE3: In .NET Framework 2.0 and above, authorization element is configured in the web.config file. NOTE4: In .NET Framework 1.1 and 1.0, authorization element is configured in the machine.config file.

Solution

Make sure 'Authorization - 'allow users'' is for unauthenticated users to view Virtual Directories, and they do not need to be secured with SSL, set allow users.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Windows

Control ID: 2b1113236847a8a5d1e5be23adb7143bdbf5317d6c702229d6b094bca12e5fb5