| |
MailSite Knowledge Base
Microsoft IIS Lockdown tool
Document #:10058
Applies To:
Synopsis: Using the new Microsoft IIS LOCKDOWN tool causes Mailsite Express to stop operating
More Information: The new security tool for IIS can lock down ASP server pages which are necessary to properly use MailSite Express.
Fresh installation of the IIS LOCKDOWN tool
When installing the IIS LOCKDOWN tool, do not choose the express option. Choose the advanced option and DO NOT disable ASP pages. If you disable ASP pages, your MailSite Express service will not function. You must also allow the anonymous IIS user to write content to directories. If you have already denied access to the anonymous user, you must either UNDO your lockdown procedure via the LOCK DOWN tool, reinstall express or enable the permissions for the pocket and express folders, please refer to the re-enabling Express and Pocket permissions below.
Correcting the IIS LOCKDOWN tool security
If you have already installed the IIS LOCKDOWN tool, and have disabled the ASP pages option, follow the instructions below to re-enable the MailSite Express service:
- OPEN the IIS management console
- Right click on the server name (computer icon) and Select properties
- Select the WWW service and click edit
- Click on the Home Directory TAB
- Click on Configuration
- On the App Mappings TAB select the ASP extension
- Click edit
- Click browse and select the ASP.DLL file
- Click OK
- Repeat steps 6 to 9 with the ASA, CDX, and CER extensions
- Click apply
- Click OK again to close
Re-enabling Express and Pocket permissions
You will need the following permissions for the Express and pocket directories, in order to restore MailSite Express and Pocket to operational status:
|
Windows NT4.0 & Windows 2000
|
| USER |
RIGHTS |
| everyone |
{RWX} {WX} |
Related:
See these other knowledge base documents:
Last revised 2006-9-29
|
|