Re: Cannot open log for source {0} -- again

craig.wagner_at_gmail.com
Date: 04/04/05

  • Next message: Nicole Calinoiu: "Re: Cannot open log for source {0} -- again"
    Date: 4 Apr 2005 08:30:13 -0700
    
    

    > When you add an existing user to a group, the new
    > group membership will not take effect until the
    > next time the access token for the account is
    > generated. For typical user accounts, this will
    > be at the next login. For the IUSR account, this
    > is far more difficult to control. The best way to
    > ensure that the token is refreshed is to reboot the
    > machine.

    I was finding this to be the case. I also found that doing an iisreset
    after changing group membership solved the problem.

    I have since been able to determine that the offending element in the
    whole thing seems to be the Guests group. If the IUSR account is a
    member of the Guests group, regardless of any other group membership
    then writing to the event log fails (i.e. IUSR could be a member of
    Administrators as well as Guests and it would still fail). I removed
    IUSR from all groups and it worked. So apparently it has nothing to do
    with the IUSR account but rather the Guests group. There must be an
    explicit "deny" somewhere in the system for that group that is causing
    the failure, but I have been unable to locate it with regmon, filemon,
    and auditing.

    > BTW, adding a user to the administrators groups
    > is not exactly the safest way to gain write access
    > to the application event log...

    I'm fully aware of that. Unfortunately, given the thundering silence
    that is the response to this problem it becomes necessary to try
    various combinations to see what might work so one can compare the
    differences between account and group permissions in an attempt to
    figure out exactly what is necessary to make it work. I realize using
    the Administrators group or Administrator account is not a long-term
    solution, it was simply another data point in trying to narrow down the
    problem.


  • Next message: Nicole Calinoiu: "Re: Cannot open log for source {0} -- again"

    Relevant Pages

    • Re: SMS Console Freezing
      ... A quick look at the smsprov.log tells us that the connection is hanging at ... the group membership enumeraion phase for the account being used to launch ... > SMS Administrator Console ...
      (microsoft.public.sms.setup)
    • IsInRole performance issue
      ... -Add that domain account to a large number of groups. ... In my test I setup netmon on the domain controller. ... number of group membership is that fact that some other application could ... I think that the framework is just implmented ...
      (microsoft.public.dotnet.security)
    • IsInRole performance issue
      ... -Add that domain account to a large number of groups. ... In my test I setup netmon on the domain controller. ... number of group membership is that fact that some other application could ... I think that the framework is just implmented ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Q about "control userpasswords2" in XP home
      ... My account is the one that all applications have been ... It might have had the "users" group membership ... the "Administrators" group membership. ... interfaces see it has membership in Users group it then ...
      (microsoft.public.windowsxp.security_admin)