Access denied when checking local group if DC is 2003
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > Access denied when checking local group if DC is 2003




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Access denied when checking local group if DC is 2003  
Craig


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
09-23-04 02:26 AM

Hello Hugh,

Sounds to me like you have not enabled some Win2003
Server IIS webservices functions and/or properly assign
the proper windows system folder system permissions so
internet visitors are allowed to access/write to the
windows system folder.

These privileges have changed in the Win2003 Server OS
now for the windows system folders.
- IIS_WPG
- IWAM

If you would like to correspond further, I have created a
temporary email address you can contact me at and if you
have a need to send image files, they are the only types
that are accept by the mail service.:

HUGH1-CONTACT-CRAIG@GNIS.NET

Sincerely,

Craig

PS: I do have a couple pieces of software that I sell,
which will remove some future heartaches if you're
interested.

- My-IISBackups: Backup and Restore settings quickly
- My-IIS: Enable any windows system folder as a domain
name record in IIS Quickly. WinServer OS's Version.



>-----Original Message-----
>We have a custom authentication .dll that takes
user/pword/domain and
>authenticates domain membership and THEN checks whether
the user is in a
>domain/global group inside a local group on the web
server.
>The code works fine and never has a problem contacting
the DC and returning
>yay/nay on domain account membership; however, if the DC
is running 2003 OS
>(with mixed or native 2000 AD) the second part of the
call can't return
>anything about membership in the local group when it
queries the local
>machine for groups. The following error occurs:
>"A system error has occurred: 5"
>"The user does not have access to the requested
information."
>
>The web server is win2k and the application is running
as IUSR_<machine>.
>The code impersonates the validated user and then sets a
session cookie to
>allow access to subsequent pages.
>I have tried using a domain account and Integrated auth
and still get the
>same error.
>Also made secpol change on DC to allow anonymous
enumeration of SAM accounts
>to no avail.
>Any ideas??
>
>
>.
>





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 11:52 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register