Send a suggestion!

We're building a brand new version of the site, and we'd love to hear your ideas

Members

Technology Zones

IBM Learning Center

Articles

Hosted By

MaximumASP

Info

Rated
Read 80,866 times

Contents

Related Categories

Mastering IIS FTP - The Doorway Folder Trick

ORCS WEB

The Doorway Folder Trick

In the previous two parts we learned how to leverage virtual directories and physical folders to offer a lot of control from IIS FTP. Now, what about when we want to have one site administrator have access to more than one, but not all, of the directories in a site? How is this accomplished from within IIS FTP?

Objective: To create a customized login with access to some of the folders in a site.

Note: For the purpose of Part 3 and Part 4, I've decided to standardize on the word “Folder” when referring to something at the disk level, and “Directory” when referring to something within IIS.

Let's view this visually so that it's easier to see where we are heading. Below is a picture of a fresh server build on Windows Server 2003 with the Default FTP Site.

I've changed the FTP root path to d:\domains which points to 7 sites that we'll pretend that I manage. You can see the site names below.

Now, in this illustration we have two different site administrators, Scott and Matt. Scott needs access to all 7 sites but Matt should only have access to microsoft.com and msn.com.

So, with that in mind, let's create an FTP account for Matt. We want one that only displays microsoft.com and msn.com in his FTP program.

It's actually quite simple really. The trick is to create what I'll call a doorway folder.

A doorway folder is simply a folder that will serve as the first step or the doorway for a particular user. The trick is to create a set of “physical” folders and “virtual” directories that will work together to display to Matt what we want him to see.

First: Create the users

Depending on your situation, you may have existing Windows users set up for Scott and Matt already. But, in case this is a new account for a new user, be sure to create a user called Matt and another called Scott . These can be Local users from within Local Users and Groups or Active Directory users, depending on your environment.

Second: Create the “physical” folders

Next we'll create a folder that holds the “physical”, but blank, sub-directory to match the real ones we want the user to have access to. This is simply so that the FTP client program displays the two folders. Let's call the root folder FTProot and the subfolder Matt, although either of these folders could be named anything. Now create two empty folders named microsoft.com and msn.com. (See Part 2 if you're not sure why) The security permissions on the folders need to give Matt at least List permissions.

Don't forget that Matt will need read and write permissions to d:\domains\microsoft.com and d:\domains\msn.com and he will need list permissions to d:\ftproot\dummyfolder and list permissions to d:\ftproot\matt.

Third: Create the “virtual” directories

Now we need to create the virtual directories that handle the redirecting. First, before we forget, if you remember from Part 1, I recommend pointing the root FTP directory to a dummy folder. So, let's create a folder in d:\ftproot called dummyfolder. Point the FTP root folder to this. Next, to handle the Scott user, create a virtual directory called Scott that point to d:\domains. Now, if Matt moves up a folder to the root folder, he won't have access to d:\domains. Instead he will be placed in d:\ftproot\dummyfolder which is a dead end. See Part 1 for more on this.

Back to the virtual directories . . .

  • In IIS, create a virtual directory called Matt .
  • This should point to d:\ftproot\matt.
  • Off the Matt virtual directory, create 2 more virtual directories
  • microsoft.com should point to d:\domains\microsoft.com
  • msn.com should point to d:\domains\microsoft.com
  • Spelling on these virtual directory names needs to be identical to the folders created in the second step above.
  • Don't forget to check read and write when creating the virtual directories if you want Matt to be able to read and write to the FTP account.

That's it!! I told you it was easy. Let's test it now.

I'll use WS_FTP to log in as the Matt user. Here is what I see in the left column:

Likewise, when logging in as Scott , we see what he is supposed to see:

In this part we didn't bring anything new to the table but we've shown that yet again MS FTP has the ability to do more than what first meets the eye.

In Part 4 we'll cover User Isolation, a new feature of IIS6.0. (Coming soon!)

Comments

  • Re: [4660] Mastering IIS FTP

    Posted by mpr104 on 05 Aug 2007

    Excellent how-to, thanks!


     


    Regards


    Matt

  • Re: [4660] Mastering IIS FTP

    Posted by maartens on 23 Dec 2006

    This was just what I was looking for. I'm running multiple websites on my w2k3 server but was in need for a good solution to excess them via FTP. The simplicity is amazing. Thanx for the readthru, kee...

  • Re: [4660] Mastering IIS FTP

    Posted by rhettkelton on 08 Jun 2006

    This is great!  Easy to understand article, and works perfectly (at least for me!)

  • Brilliant!

    Posted by Gerrit on 31 May 2005

    :D Wow! That easy. Thanx this one really solved a lot of problems for me!

    One question though, (Please note that I am a complete newby at this), Why does my servers performance drop (signifficantl...

  • Posted by James Crowley on 26 Apr 2005

    Nice! Cheers for those extra tips, Eric :)