RE: Secure Ldap call not working due to IUSR/IWAM permissions?

From: dave (dave@netmedic.net)
Date: 02/01/03

  • Next message: Ghost: "IIS Security using Integrated Windows Authentication"
    From: "dave" <dave@netmedic.net>
    To: "'Turner, Keith (Contractor)'" <Keith.Turner@tea.army.mil>, <focus-ms@securityfocus.com>
    Date: Fri, 31 Jan 2003 18:54:33 -0500
    
    

    You mention server hardening.
    What methods did you use for hardening?
    Did you run IISLockdown?

    There is obviously some access you took away during your "server hardening"
    process, which is needed.

    595 is a successful object access, and 560 is a successful object open, I am
    not sure what the references to those are.

    Dave

     
    _____________________
    Dave Kleiman
    dave@netmedic.net
    www.netmedic.net

     

    -----Original Message-----
    From: Turner, Keith (Contractor) [mailto:Keith.Turner@tea.army.mil]
    Sent: Friday, January 31, 2003 13:33
    To: focus-ms@securityfocus.com
    Subject: Secure Ldap call not working due to IUSR/IWAM permissions?

    I am trying to get LDAP working so that I can authenticate web users against
    an iPlanet directory server. There appears to be something on the machine
    which prevents IUSER or IWAM from making the LDAP call. My best guess is
    that something which was done during server "hardening" is preventing this
    from working. When using network monitor, I see that no packets are placed
    on the network. I have enabled auditing for global system objects and it
    does show audit failures when the LDAP call fails. I have used FileMon and
    RegMon (sysinternals) to watch for file or registry failures, but none
    showed up.

     There about 20 fails for each LDAP attempt, but there are only two unique
    events

    1) id 595
    Indirect access to an object has been obtained
    object type: port
    object name: \RPC Control\DNSResolver
    Accesses: Communicate using port

    2) id 560
    Object name: \Device\NetBT_Tcpip_{alphanumeric string}
    Accesses: Synchronize, ReadData, WriteData

    If I replace the hostname in the opendsobject call with the ip address, the
    call makes it to the server (can see it in network monitor), but then fails.
    I assume it is failing because the ip address doesn't match the hostname
    provided in the SSL certificate. If I place the IUSR/IWAM accounts in the
    local admin group, everything works properly (calling the directory server
    by hostname). The error always occurs on this line of the asp file :
    Set oContainer = oLDAP.OpenDSObject(Server & dnUserName, dnUserName,
    sPassWord, 2)

    Anyone have any ideas?
    Thanks, Keith



    Relevant Pages

    • RE: Proxy+ Trojan
      ... Who and what did the server hardening? ... OS or the applications you have running. ... and I'm ok now (except for learning how to configure the firewall :-)). ...
      (Security-Basics)
    • Re: Does samba 3.0.14Aa on OS 5.0.6 work with ldapsam backend on another LDAP server?
      ... used 3.0.9 on SCO 5.0.6 for quite some time after suffering problems I ... a RedHat4 box running samba 3.0.10 and OpenLDAP 2.2.13. ... and no LDAP server (although there were the ... share on the SCO server without any smbpasswd on that server! ...
      (comp.unix.sco.misc)
    • RE: LDAP & Find People not working
      ... need to refer to the KB article below to know how to use LDAP: ... | Yes, the scanner is on the local area network, so as you indicated below, ... | So I wonder why the scanner does not see the LDAP server. ...
      (microsoft.public.windows.server.sbs)
    • slapd - slow starting
      ... contact LDAP server ... then slapd started fine but I without ldap in nsswitch.conf I cant ... # The user ID attribute (defaults to uid) ... # SSL enabled. ...
      (freebsd-stable)
    • Re: Configuring LDAP on Entourage 2004 OS X
      ... On the SBS server box, open Server Management console, navigate to ... by companies that are independent of Microsoft. ... Configuring LDAP on Entourage 2004 OS X ...
      (microsoft.public.windows.server.sbs)