Re: Problems with IsInRole

From: Joe Kaplan \(MVP - ADSI\) (joseph.e.kaplan_at_removethis.accenture.com)
Date: 11/18/04

  • Next message: wh1974: "security issues regarding the "ManagementObjectSearcher" object"
    Date: Wed, 17 Nov 2004 21:08:15 -0600
    
    

    That's too bad. I've seen these kinds of problems, but they are pretty
    mysterious.

    You could also try using some Directory Services code to do this to overcome
    the issue with the LSA, but that will require more config and potentially be
    more brittle.

    Perhaps there is a way to solve the trust issue though. I'm the wrong guy
    to ask there, but I'm sure someone understands the options.

    Joe K.

    "John Rusk" <JohnRusk@discussions.microsoft.com> wrote in message
    news:AE2E348F-4FF9-444B-9B6B-B2E0A397C315@microsoft.com...
    >I think I've found the problem. I think its something like this:
    >
    > http://support.microsoft.com/default.aspx?scid=kb;en-us;262958
    >
    > While I'm not 100% sure that I'm suffering from _exactly_ the same
    > problem,
    > it seems that its possible to configure domain controllers in a way that
    > breaks .NET's role based security.
    >
    > I ended up dropping .NET's IsInRole, and using equivalent code from Keith
    > Brown's security library
    > (http://www.theserverside.net/discussions/thread.tss?thread_id=25074).
    > That
    > was when I finally got the error 1789, which means "The trust relationship
    > between this workstation and the primary domain failed". It's a shame
    > that
    > .NET's IsInRole doesn't log anything to indicate what's going wrong. The
    > only sign was blank/missing names for global groups when I called
    > _GetRoles.
    >
    > In the code I used, from Keith Brown's library, it was the translation
    > from
    > names to SIDs that was failing.
    >
    > Thanks for your suggestions Joe.
    >
    > John
    >
    >


  • Next message: wh1974: "security issues regarding the "ManagementObjectSearcher" object"

    Relevant Pages

    • Re: Check group membership, the sequel
      ... ...and i agree with Joe - IsInRole is the way to go and it MUST work. ... IsInRole supports fully nested security group membership (assuming you are ... > how to handle users depending on their group memberships, ...
      (microsoft.public.dotnet.security)
    • Re: Okay, Kris.....
      ... But she's NOT KEITH! ... Get rid of Tucker Carlson ... That doesn't explain Joe Scarborough. ... Aruban law and how to solve the case than professional law ...
      (alt.true-crime)
    • Re: Problems with IsInRole
      ... While I'm not 100% sure that I'm suffering from _exactly_ the same problem, ... I ended up dropping .NET's IsInRole, and using equivalent code from Keith ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: 2003 SBS Monitor & Reporting - Email not showing sent activity when there is activity.
      ... Joe - There is no data available for this statistic. ... > Best Regards, ... > Keith Rutledge, MCSE NT4/2000 ...
      (microsoft.public.windows.server.sbs)
    • Re: joe the slapper?
      ... to be honest i did think Joe would ... done Joe a great fight. ... Keith ... He was like Corbett against Sullivan. ...
      (rec.sport.boxing)