LsaRegisterLogonProcess : Access denied

frank.thiry_at_gmail.com
Date: 05/25/05


Date: 25 May 2005 12:18:39 -0700

Hi all,
I'm using the LSALogonUser (s4uLogon). I'm trying to connect with the
LsaRegisterLogonProcess but this one fails
(STATUS_PORT_CONNECTION_REFUSED) even if my calling process (account
define in the Application Pool) have the SeTcbPrivilege (Act as part of
operating system).
I'm definetly need a token with SecurityImpersonation as Impersonation
level (using LsaConnectUntrusted give me a SecurityIdentification, not
enough for impersonation).

The account is define in my AD (Service account), localy the
SeTcbPrivilege is OK, this account is also domain controller. is
running the w3s service.
I'm using the Windows Authentication mode (IIS 6) and i'm running on a
win2003 box.

please tell me how to connect with LsaRegisterLogonProcess.
Thanks a lot,

FT



Relevant Pages

  • Re: Azman: AzAuthorizationStoreClass.Initialize
    ... The service account we are using to do impersonation ... I add to the serice account to the reader role in ADAM. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SetPassword access denied
    ... safely invoke SetPassword etc..... ... impersonation or using the process token without impersonation) is NOT ... account that is used for performing remote activities in the directory. ... Co-author of "The .NET Developer's Guide to Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: VS.NET 2005 and the "allowDefinition=MachineToApplication" error
    ... Your description of impersonation is great. ... If you want to use the default configured account, eliminate that entry, or configure it as: ... The easiest way to assign correct permissions to all required directories is to run: ... I re-started IIS and tried to access my ASPX page again -- same ...
    (microsoft.public.dotnet.framework.aspnet)
  • [Full-disclosure] Maybe nothing so shady; depends on the motive.
    ... There may be no impersonation going on. ... attempted use of a disabled account would produce messages about "account foo login fail" ... SecureWorks was still reading email addressed to David Maynor. ...
    (Full-Disclosure)
  • Re: SetPassword access denied
    ... That said, I think one thing worth pointing out is that in both cases here, your code is supplying credentials to the DirectoryEntry constructor. ... the identity of the current thread (established either via impersonation or using the process token without impersonation) is NOT the account that is used for performing remote activities in the directory. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)