Re: anonymous access denied

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 03/05/04

  • Next message: Jean: "Installing SSL after server has been re-formatted"
    Date: Fri, 5 Mar 2004 00:19:13 -0700
    
    

    When you dcpromo a DC down the existing domain
    accounts are invalidated. Since your IIS installation
    was done after the SBS2k3 server was a DC, all of
    the backend and access accounts are now invalid.

    The most direct route to establishing a functioning
    IIS at this point, assuming you do want to keep the
    machines as a non-DC (an expensive use of an SBS2k3
    license) is to secure copies of your web content to a
    separate location, and to then uninstall and reinstall
    IIS, followed by re-establishing the content. This will
    cause the needed backend and access accounts and their
    wiring to be hooked up for the account database as it now
    exists.

    -- 
    Roger Abell
    Microsoft MVP (Windows Server System: Security)
    MCSE (W2k3,W2k,Nt4)  MCDBA
    <gv> wrote in message news:%23f3rfpnAEHA.684@tk2msftngp13.phx.gbl...
    > I removed AD from my webserver (win 2k3 small bus edition) and now my web
    > sites say that I am not authorized to view the page (even from the web
    > server itself).  I check IIS (6.0) and it definitly has allow anonymous
    > checked, I made sure that there is no integrated security checked, I also
    > opened up the permissions thru IIS and on the disk, but still no go.  I
    even
    > gave the IUSR account admin rights, but still no go.  And of course a
    wizard
    > that allows you to configure the server, was available before I removed AD
    > is now no longer available.  The web sites worked fine until I removed AD.
    > I didn't install AD on this box, it came already setup from dell.  I
    > successfully installed AD & DNS on another box, and now removal of it from
    > my webserver has caused my websites to not accept anonymous
    authentication.
    > It seems that anonymous access is no longer allowing anonymous access.
    When
    > I do have the intergrated security checked off, I can authenticate (with
    > admin only, IUSR does not authenticate) and view the web site normally.  I
    > think removing active directory messed up either the IUSR account or some
    > other security policy.
    > Any help will be greatly appreciated.
    > Thanks
    > gv
    >
    > ps I just did a search on this NG for my subject and I did pretty much try
    > everthing that I've seen for answsers and still no go.
    > ie, made sure passwords for the IUSR accounts matched in IIS and the user
    > account, checked the local security policy and made sure IUSR had access
    to
    > allow log on locally, and access the computer from a network,
    >
    >
    

  • Next message: Jean: "Installing SSL after server has been re-formatted"

    Relevant Pages

    • Re: IIS Anonymous Access Issue
      ... accounts might have been restricted or disabled. ... > IIS will not, under any security configuration allow anonymous website ... > Security for IIS: Anonymous access is enabled under the IUSR_SEAWOLF ... Without IWA enabled the server gives a standard 403 ...
      (microsoft.public.inetserver.iis)
    • Re: 2003 server hangs at Applying Computer Settings - Cant login
      ... Or maybe the server was configured to auto-login the administrator -- and ... has always been catestrophic and requires reinstalling IIS. ... > accounts still loaded in memory, and therefore Exchange and other services ...
      (microsoft.public.windows.server.general)
    • Re: Please help refresh my memory on AD DC
      ... use only domain user accounts. ... "Meinolf Weber" wrote: ... Remote server ... Also that one for IIS. ...
      (microsoft.public.windows.server.active_directory)
    • RE: IIS Integrated Windows Authentication problem
      ... to "Show friendly HTTP error messages." ... Make sure that all the accounts have the "Access this computer from the ... > - After extensive searching in the IIS logs, ... >>to Integrated Windows Authentication only. ...
      (microsoft.public.inetserver.iis.security)
    • Re: CGI apps break after DCPROMO an IIS6 server
      ... This is one of those things different on a DC vs a member server in regards ... The "built in" accounts have the minimum and necessary privileges to run ... >privileges listed in F1-help of IIS Manager UI required ...
      (microsoft.public.inetserver.iis.security)