Bloccato Website logon extensibility

  • 2010年4月29日 14:49
     
     
    How extensible is the website logon in Vail? I'd really like to add an additional authentication factor (OTP, etc). Has any thought toward this gone into the Vail website design?

所有回覆

  • 2010年4月29日 14:55
    版主
     
     已答覆
    Have you consulted the SDK (available on Connect ) to see what's available there? I see several assemblies documented that are related to the web...
    I'm not on the WHS team, I just post a lot. :)
  • 2010年4月29日 19:37
     
     

    Thanks Ken,

    I'll look into it when I get a chance. I was hoping someone might know off the top of their head, or some MS folks could comment.

    Am I alone in thinking we should have an easy option to add some more security to the WHS web portal? Its a bit pitiful if there is less protection around a gateway from the web to all your files than for your World of Warcraft account (supports OTPs).

    You and I have had this discussion before at some point, but I haven't heard any MS opinions either way.

  • 2010年4月29日 20:04
    版主
     
     

    Yes, we have. :)

    Basically, IIS doesn't preclude the use of one time passwords, whether distributed by means of tokens, SMS, apps on cell phones, etc. But you will need to shoehorn that into the Remote Access web site, and that I don't see happening. It's an ASP.Net web application (quite a slick one, I think), so if Microsoft hasn't provided hooks to modify the security, you'll be out of luck.


    I'm not on the WHS team, I just post a lot. :)
  • 2010年4月29日 20:22
     
     
    Yup, I'm hoping things are more extensible this time, so that shoehorning is no longer required. I suppose I should have submitted a connect suggestion a while ago. But honestly, sometimes, important as it is, I feel like I'm the only one that cares about this stuff for the home setting. Not sure why, seems like there are plenty of paranoid people around :)
  • 2010年4月29日 20:35