Re: Resetting IUSR user token

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 06/26/05

  • Next message: Marlon Brown: "Re: Trying to understand this behavior, Ports in IIS"
    Date: Sun, 26 Jun 2005 03:30:09 -0700
    
    

    IIS does not expose any programmatic access for users to insert/invalidate
    any of its internal caches, so you will have to find a workaround. I do not
    understand why you ACL the folder to only the new local group -- why don't
    you ACL the folder to also include Authenticated Users or IUSR since the
    effective ACL does not change -- but now you do not get affected by the
    token cache.

    And I still think that your design of inserting IUSR into various Windows
    user groups to be weird. It is not clear to me what you are actually gaining
    vs what I had described earlier. Why are you adding IUSR to various user
    groups?

    The real issue here is that when a user account's group membership changes,
    there is no way for IIS to get a change notification -- or else the token
    cache would just work. Giving programmatic access for users to
    insert/invalidate the token cache is clearly not the solution; it is just
    one of many possible workarounds.

    -- 
    //David
    IIS
    http://blogs.msdn.com/David.Wang
    This posting is provided "AS IS" with no warranties, and confers no rights.
    //
    "Ard" <Ard@discussions.microsoft.com> wrote in message
    news:F57CE627-8327-4F5D-A7DF-9526173F788A@microsoft.com...
    Folks,
    Maybe someone can help me out here.
    I'm working on an ASP web application on a w2k server with iis 5.
    The application dynamically creates folders and uses adsi to create local
    windows groups that have access to these folders.
    Because the group 'authenticated users' is member of one of the new windows
    groups, the IUSR account should have access to the new folder. But because
    the IUSR user token is cached for 15 mins anonymous users can't immediately
    access this folder, but have to wait untill the TimeToLive for the IUSR
    token
    has expired.
    Because of the performance penalty i don't want to reduce the UserTokenTTL
    for all users. (The possible solution described in KB152526.)
    Is it possible to force the expiration of the IUSR user token? If I can
    expire just this one token immediately after creating the windows groups,
    the
    problem should be solved.
    Does anyone know a way to accomplish this?
    

  • Next message: Marlon Brown: "Re: Trying to understand this behavior, Ports in IIS"

    Relevant Pages

    • Re: Synchronize of profile and user share folder
      ... With method two, when the cache is clear and offline will not be available, ... share folder do not sync when you logon and log off the computer. ... Open windows explorer, click Tool menu, select Synchronize. ... The Offline Files cache on the local computer will be re-initialized. ...
      (microsoft.public.windows.server.sbs)
    • Re: File System Object Lockdown...possible?
      ... When I simply add the IUSR account to the folder and DENY write acess, ... > global.asa and IWAM have very little to do with the situation. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Resetting IUSR user token
      ... folder would be the way to go: ... > And I still think that your design of inserting IUSR into various Windows ... > insert/invalidate the token cache is clearly not the solution; ... > windows groups that have access to these folders. ...
      (microsoft.public.inetserver.iis.security)
    • Re: caching problem
      ... > popping up from the cache. ... > 2) delete TIFs folder, history folder and cookies folder from the local ... > service and DHCP client service disabled to avoid system slow downs. ... > have been experimenting with the DNS client service and DHCP client ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: caching problem
      ... The IE cache is ... Another program interfering with IE. Try disabling third party programs ... >>> 2) delete TIFs folder, history folder and cookies folder from the local ... >>> service and DHCP client service disabled to avoid system slow downs. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)