Seriously, what the hell?!

O.k., URL Scan is a great tool. I personally think it is stupid that it is a separate download for IIS, but I am not the one releasing it so whatever. Here is my major confusion though. When you install URL scan you get no warning that you could possibly break things on your web server and it installs and then implements default security policies on its own. I cannot install the tool, leaving it disabled, configure it to my hearts content, then apply the changes to make it live. Gah! Granted I should have tested the tool first, but what if I do not have a testing web server? I just applied it to a live machine and our main app just died and I could not figure out why it was not working. I uninstalled URL Scan for the fix, and then figured out what I had to do. Install, reconfigure while the app is broken, then reinstall. So now I have to have downtime, no matter what. Granted it is only a few seconds, but what if this was a big site where that would mean SERIOUS moola? Also, it has a default allow as the default setting, only certain extensions are banned, versus certain extensions being allow. Weaksauce.

Technorati Tags: , , ,

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.