RE: Secure Ldap call not working due to IUSR/IWAM permissions?

From: Turner, Keith (Contractor) (Keith.Turner@tea.army.mil)
Date: 02/05/03

  • Next message: Adam H.Pendleton: "Re: Unknown Windows 2000 files?"
    From: "Turner, Keith (Contractor)" <Keith.Turner@tea.army.mil>
    To: 'Tony Gordon' <tony.gordon@hewitt.com>
    Date: Wed, 5 Feb 2003 13:44:56 -0500 
    
    

    Thanks Tony! That hotfix did the trick.
      I'm assuming that some of the settings I changed before installing sp3 is
    what lead to this problem. I have other machines I have configured the same
    way, but they were postsp3 - so the configuration changes were done after
    sp3 was installed.

    Keith

    -----Original Message-----
    From: Tony Gordon [mailto:tony.gordon@hewitt.com]
    Sent: Monday, February 03, 2003 5:32 PM
    To: Turner, Keith (Contractor)
    Cc: focus-ms@securityfocus.com
    Subject: Re: Secure Ldap call not working due to IUSR/IWAM permissions?

    If this is W2K with SP3 take a look at
    http://support.microsoft.com/default.aspx?scid=kb;en-us;329405. MS
    changed some security stuff after which users who are not admins cannot
    resolve names. The fix worked for us.

    Thank you, Tony.
    Tony Gordon, Windows 2000 MCSE
    tony.gordon@hewitt.com
    Windows Server Infrastructure
    Phone: 847.295.5000 x14534
    Fax: 847.295.8877
    Hewitt Associates

    "Turner, Keith (Contractor)" <Keith.Turner@tea.army.mil>
    01/31/2003 12:33 PM

     
            To: focus-ms@securityfocus.com
            cc:
            Subject: Secure Ldap call not working due to IUSR/IWAM
    permissions?

    I am trying to get LDAP working so that I can authenticate web users
    against
    an iPlanet directory server. There appears to be something on the machine
    which prevents IUSER or IWAM from making the LDAP call. My best guess is
    that something which was done during server "hardening" is preventing this
    from working. When using network monitor, I see that no packets are placed
    on the network. I have enabled auditing for global system objects and it
    does show audit failures when the LDAP call fails. I have used FileMon and
    RegMon (sysinternals) to watch for file or registry failures, but none
    showed up.

     There about 20 fails for each LDAP attempt, but there are only two unique
    events

    1) id 595
    Indirect access to an object has been obtained
    object type: port
    object name: \RPC Control\DNSResolver
    Accesses: Communicate using port

    2) id 560
    Object name: \Device\NetBT_Tcpip_{alphanumeric string}
    Accesses: Synchronize, ReadData, WriteData

    If I replace the hostname in the opendsobject call with the ip address,
    the
    call makes it to the server (can see it in network monitor), but then
    fails.
    I assume it is failing because the ip address doesn't match the hostname
    provided in the SSL certificate. If I place the IUSR/IWAM accounts in the
    local admin group, everything works properly (calling the directory server
    by hostname). The error always occurs on this line of the asp file :
    Set oContainer = oLDAP.OpenDSObject(Server & dnUserName, dnUserName,
    sPassWord, 2)

    Anyone have any ideas?
    Thanks, Keith



    Relevant Pages

    • Problems with LDAP over SSL
      ... Windows 2000 Server box with SP3. ... CA and created a valid cert, but SSL LDAP connections to ...
      (microsoft.public.win2000.security)
    • Re: Does samba 3.0.14Aa on OS 5.0.6 work with ldapsam backend on another LDAP server?
      ... used 3.0.9 on SCO 5.0.6 for quite some time after suffering problems I ... a RedHat4 box running samba 3.0.10 and OpenLDAP 2.2.13. ... and no LDAP server (although there were the ... share on the SCO server without any smbpasswd on that server! ...
      (comp.unix.sco.misc)
    • RE: LDAP & Find People not working
      ... need to refer to the KB article below to know how to use LDAP: ... | Yes, the scanner is on the local area network, so as you indicated below, ... | So I wonder why the scanner does not see the LDAP server. ...
      (microsoft.public.windows.server.sbs)
    • slapd - slow starting
      ... contact LDAP server ... then slapd started fine but I without ldap in nsswitch.conf I cant ... # The user ID attribute (defaults to uid) ... # SSL enabled. ...
      (freebsd-stable)
    • Re: Configuring LDAP on Entourage 2004 OS X
      ... On the SBS server box, open Server Management console, navigate to ... by companies that are independent of Microsoft. ... Configuring LDAP on Entourage 2004 OS X ...
      (microsoft.public.windows.server.sbs)