1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

403 Forbidden Error Due to Wrong Impersonation Level

Discussion in 'Microsoft News' started by NewsBot, Apr 30, 2008.

  1. NewsBot

    NewsBot I Got News

    Joined:
    Feb 8, 2006
    Messages:
    1,813
    Operating System:
    Windows Vista Home Premium
    I'm using HttpWebRequest and HttpWebResponse to query a remote server. I plan to load the returned xml into an XMLDocument, but the HttpWebRequest.GetResponse() method fails with a 403 "Forbidden" error.

    I am able to get a response when I put my domain username and password as plain text into the request's Credentials member, but of course I'd like to avoid having that information in the application.

    I thought that code along these lines (found at )
    would solve my problem:

    using <!--coloro:#408080--><span style="color:#408080 <!--/coloro-->System.Security.Principal;<!--colorc--><!--/colorc-->

    <!--coloro:#0000ff--><span style="color:#0000ff <!--/coloro-->if<!--colorc--><!--/colorc--> (User.GetType() == <!--coloro:#0000ff--><span style="color:#0000ff <!--/coloro-->typeof<!--colorc--><!--/colorc-->(<!--coloro:#408080--><span style="color:#408080 <!--/coloro-->WindowsPrincipal<!--colorc--><!--/colorc-->))
    {
    <!--coloro:#408080--><span style="color:#408080 <!--/coloro-->WindowsIdentity<!--colorc--><!--/colorc--> id = (<!--coloro:#408080--><span style="color:#408080 <!--/coloro-->WindowsIdentity<!--colorc--><!--/colorc-->) User.Identity;
    <!--coloro:#408080--><span style="color:#408080 <!--/coloro-->WindowsImpersonationContext<!--colorc--><!--/colorc--> impersonate = id.Impersonate();

    <!--coloro:#008000--><span style="color:#008000 <!--/coloro-->//perform tasks under the impersonated user
    //*** ***// <!--colorc--><!--/colorc-->
    <!--coloro:#008000--><span style="color:#008000 <!--/coloro-->//revert back to local ASPNET account<!--colorc--><!--/colorc-->
    impersonate.Undo();
    }
    <!--coloro:#0000ff--><span style="color:#0000ff <!--/coloro-->else<!--colorc--><!--/colorc-->
    {
    <!--coloro:#008040--><span style="color:#008040 <!--/coloro-->//user isn’t authenticated<!--colorc--><!--/colorc-->
    }
    But, I still get the 403 error. I think the impersonation is failing because the WindowsIdentity.ImpersonationLevel property is always "Impersonation." I think this needs to be "Delegation" to reach the remote server (I'm behind a firewall and corporate proxy), but the property is read-only so I can't set it.

    My Question: What do I need to configure in order to get the ImpersonationLevel property to be of the TokenImpersonationLevel.Delegation type?

    Let me know if this requires clarification.






     

Share This Page