Impersonation/Delegation security considerations

From: Rich (rich_at_dha.net)
Date: 08/25/03


Date: Mon, 25 Aug 2003 08:48:23 -0700


I'm having trouble finding specific documentation
regarding the negative impact of using delegation in a
Windows 2000 environment. I've read through numerous
articles on using it, but if I do find anything that
cautions the use of it, it reads like the following:

Important:Delegation is a very powerful feature and is
unconstrained on Windows 2000. It should be used with
caution. Computers that are configured to support
delegation should be under controlled access to prevent
misuse of this feature.

Our Network/Server side of the house does not want to
implement delegation without knowing the immediate and
potential security risks, and how to guard against them.



Relevant Pages

  • Re: Propagating caller identity across applications from a bare ASMX Service method to a WSE3 Servic
    ... Directory Domain as the server computer and the server App Pool run-as ... Windows 2003 Server mode -- they may be in Windows 2000 mixed mode. ... to be configured so as to use kerberos delegation. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: "Account is trusted for delegation" is not shown
    ... Where SPN is the servicename/computername (MESSENGER/SERVERNAME for ... This will add the delegation tab to the useraccount you specified. ... account with the Setspn utility in the support tools on your CD. ... It should be caused by raising functional level to windows 2003. ...
    (microsoft.public.windows.server.general)
  • Re: kerberos sudenly stop working on an IIS server
    ... D_DebugLogClient %wZ sent AS request with no server name\n") ... Windows XP and Windows Server 2003 will recover from this automatically. ... For information about setting up service accounts for delegation, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Given access to edit active directory
    ... And if we're mentioning third party tools to help with this, ... DSRAZOR for Windows. ... Once you get the delegation part using the built-in ...
    (microsoft.public.windows.server.active_directory)
  • RE: accessing WebService from asp.net App on load balanced Servers
    ... for intranet application within a windows domain ... For general info on ASP.NET delegation: ... Servers ... | | Subject: RE: accessing WebService from asp.net App on load balanced ...
    (microsoft.public.dotnet.framework.aspnet.security)