Showing posts with label IIS. Show all posts
Showing posts with label IIS. Show all posts

Thursday, February 19, 2015

ASP.NET Web Api 404 errors

I recently deployed a ASP.NET Web Api web service to a production server and kept getting 404 errors when I made requests.  After extensive research I finally traced the problem to the web.config file.  I don't totally understand why this fixed it, but it has something to do with how IIS resolves the URL.

In the web.config, you'll find this line:

<add name="ExtensionlessUrlHandler-Integrated-4.0" path="*." verb="*" type="System.Web.Handlers.TransferRequestHandler" preCondition="integratedMode,runtimeVersionv4.0" />

This needs be changed to:

<add name="ExtensionlessUrlHandler-Integrated-4.0" path="*" verb="*" type="System.Web.Handlers.TransferRequestHandler" preCondition="integratedMode,runtimeVersionv4.0" />

Notice the removal of the period from the "path" attribute.

Monday, April 7, 2014

ASP.NET Membership Encryption and View State Encryption/Validation

When using .NET's Membership provider to implement Forms Authentication in your application, the user names and passwords are encrypted in the database (aspnet_Membership) table.  You must specify the encryption method and a key to perform the encryption and decryption in the web.config file.  This is where this is specified:

<system.web>
    <machineKey decryptionKey="YOUR KEY GOES HERE" decryption="AES" />
<system.web />

Despite the name, the decryption and decryptionKey attributes are not only used for decryption but are also used for encryption.  This tells Membership how to encrypt passwords and usernames in the database.  It will also tell ASP.NET how to encrypt the View State if you are configured to encrypt the View State.  This decryption attribute is set to AES.  This is the standard for encryption at the time of this writing.  In fact the decryption attribute's default is AES.  Triple DES (3DES) is also acceptable if you have older DES stuff.

How do you generate a decryptionKey?  Click on the application in IIS, and double click the Machine Key icon.  Here you can select the Generate Keys option on the right to generate a key for you.  If you click Apply, it will update the machineKey node in the web.config file with the information.

The validation and validationKey attributes are only used to validate the View State.  A hash value is created by using the validationKey and the hash function specified by the validation attribute.  This hash value is compared to what it initially was when it was sent by the browser to what is is when the server receives it.  If they are different, then the server knows that the View State was tampered with.  The validation attribute is set to "SHA1" by default.  You don't necessarily need to generate a validationKey.  ASP.NET can generate one each time a request is made.  However, if you have multiple load balanced web servers, then you must generate a validationKey so that the servers can share the Session Id.  You would follow the same procedure in IIS to generate a validationKey if you so desire.  Here is an example of the machineKey node with both validation and decryption attributes configured.

<system.web>
    <machineKey validationKey="YOUR KEY GOES HERE" 
        decryptionKey="YOUR KEY GOES HERE" decryption="AES" validation="SHA1" />
<system.web />

How to encrypt the View State

Saturday, April 5, 2014

How to enable SSL on a web site in IIS


  1. Open IIS.
  2. Click the root node in the tree view at the left.
  3. Double click Server Certificates.
  4. In the list on the right, choose either Create Self Signed Certificate or Import.
  5. Click the site you want to secure.
  6. Click Bindings on the right and click Add.
  7. Choose https and select the certificate in the drop down list.
That's it.  Now you're site is listening on port 443 (default for https requests).  If you're using a self-signed certificate, your browser will throw up all kinds of red flags, but you are encrypted now.

Lots of good info here.

ASP.NET IIS Registration Tool (aspnet_regiis.exe)

Let's say you install a new version of Visual Studio which also installs a new version of the .NET Framework.  If you are using IIS (not IIS Express) on your local PC to host a site you are developing, it won't work until you register the new version of the framework with IIS by using the registration tool.  The tool exists in each version of the frameworks folder.  Just browse to the folder of the framework you want to register and run the tool with the -i option.

Open a Command Prompt as an administrator.

cd C:\Windows\Microsoft.NET\Framework64\v4.0.30319 for example.

Then, aspnet_regiis.exe -i

MS info on tool

Friday, March 28, 2014

"Classic" ASP

"Classic" ASP is the version of ASP that existed prior to ASP.NET being introduced in 2002.  It was only given the name "Classic" after ASP.NET superseded what was then called just ASP.  A Classic ASP site consists of a bunch of .asp files with associated .html, .js, and .css files.  Nothing within a Classic ASP site is compiled.  It is all interpreted at run-time, which is why ASP.NET offered performance gains.  An .asp page is just HTML with a bunch of server scripts inside of <% ... %> tags.  The scripting language of choice is VBScript although technically you could use JScript (not to be confused with Javascript).

Of course, no one writes "Classic" ASP anymore.  But you may have an old application that you need to host while you ponder a rewrite.  Here are a few things you'll need to do if you don't have a time machine:

  1. Classic ASP is disabled by default in IIS.  Go to Control Panel, Programs, Turn Windows features on or off.  Expand Internet Information Services, World Wide Web Services, and Application Development Features.  Check the ASP box.
  2. Set up the site in IIS like you normally would.
  3. By default, you're not going to see error messages that you need to see.  Open up IIS as an administrator and double click the ASP icon under IIS.  Expand Debugging Properties, and set Send Errors to Browser to True.
  4. Then, if you're using IE, you need to go into Internet Options, on the Advanced tab, and uncheck the box for Show friendly HTTP error messages.

Thursday, December 26, 2013

Debug .NET web applications without timing out

This happens when you are hosting the web application in IIS.  Just open up IIS, click on the application pool and go to Advanced Settings.  Set Ping Enabled to False.  Apparently IIS pings itself occasionally and if it doesn't get a response, then it shuts down.  Keep in mind that while you are debugging, IIS is blocking all other requests, so it sees this as a bad thing.  So turning this behavior off during development is fine.

Friday, December 20, 2013

Manage file extensions served by a web server

If your web site exposes files for users to open, and certain file types open and certain file types don't, then you will need to add the extensions that aren't working to the MIME Types associated with the site in IIS.

  1. Open up IIS
  2. Select the Site, and choose MIME Types in the IIS section.
  3. Click on Add, and add the extension.

A quick google search should obtain the MIME Type for the extension you want to add.

Wednesday, December 11, 2013

Implementing Windows Authentication

Windows authentication essentially means you are letting users into your web site if they have a valid AD user id and password in a specified group.  It is simple and works great for an intranet application.  It's important to note that IIS is responsible for the actual authentication.  So first, you need to enable Windows Authentication for the site.  To accomplish this:
  1. Open IIS.
  2. Select the site.
  3. Click "Authentication" in the IIS group.
  4. Disable "Anonymous Authentication"
  5. Enable "Windows Authentication"
It's possible that Windows Authentication has not been installed on the web server.  If this is the case, you will need to enable that feature through the control panel.

At this point, when a user browses to your site, the browser will see that anonymous authentication is disabled and will display a login box because of the windows authentication.  Once, the user authenticates, IIS sends the user information to the actual web application.  At this point, it is up to the web application to authorize the user.  

This authorization is configured in your web.config.  Here is an example that restricts access to users in a certain AD group:
<configuration>
    <system.web>
        <authentication mode="Windows" />
        <authorization>
            <allow roles="PowerUsers" />
            <deny users="*" />
        </authorization>
    </system.web>
</configuration>
Remember that the allow element takes precedence of the deny element.

To get the user name on an aspx page, simply type User.Identity.Name.  To get the user name in .net server side code, use the fully qualified System.Web.HttpContext.Current.User.Identity.Name.

Tuesday, July 9, 2013

"Unable to Start Debugging on the Web Server" error when hosting your web application on your local IIS

It works fine when you host your project using the Visual Studio Development Server, but when you choose IIS, you get this error.  Try the following from a command prompt:

%SystemRoot%\Microsoft.NET\Framework64\{version number goes here}\aspnet_regiis -i

I think this happens when IIS doesn't recognize the version of the .net framework that you are running.  So this might happen when you install a Service Pack for instance.  Anyway, this line of code makes the version known to IIS.  Keep in mind that if you are running version 3.5 that you find this aspnet_regiis executable in the folder for version 2.0.  3.5 shares a common CLR with 2.0.