| haksly 2005-04-01, 5:54 pm |
| Hello,
I have a two-tier scanario of AC deployment (RoutingCluster + COM+Cluster,
all are Win2003Srv Ent. with the latest security patches installed except
Win2003 SP1). All call for components are redirected to COM+ cluster nodes
from Routing Cluster and executed as expected.
But I've noticed a strange thing - all call from Routing CLuster to
COM+Cluster are made under the ANONYMOUS LOGON\NT AUTHORITY account. It
doesn't fit in the secutiry concept because I have to give all the necessary
rights to this account on all COM+ cluster node in order to run COM+
Applications. This behaviour dosn't depend from account that is configured
in Identity tab of Application Properties in COM+ Explorer - I've seen no
difference either is it a valid domain account or systems account.
Could you andvice me the way to change ANONYMOUS LOGON\NT AUTHORITY account
to some other for component calls made from Routing Cluster to COM+ cluster?
Could you point me to any whitepaper or security guide that covers this
area?
BR Sergey,
MCSE
|