COM+ App Proxying With Windows 2003

From: Craig (Craig_at_discussions.microsoft.com)
Date: 09/03/04


Date: Fri, 3 Sep 2004 05:09:03 -0700

Hi,

We have two Win2000 servers that use DCOM COM+ Application Proxying to
perform their business logic. And it all works fine. The servers are
standalone, and not in a common workgroup or domain. On each machine we have
a local account that has the same password.

Now this works fine.

However, we're looking at upping one of the boxes to 2003. But we've run
into problems.
Basically, we cannot get the app proxy to work.
We get errors in event log like

DCOM got error "General access denied error " from the computer
xxx.xxx.xxx.xxx when attempting to activate the server:
{2213E314-A127-4F86-94AD-69A067F5B2CB}

Now I seem to remember that you cannot app Proxy across domains due to
security restrictions. Which leads me to believe that the only reason the app
proxying is working at the moment, is because the username and passwords are
the same on both machines. Which leads nicely into why it doesn't work with
2003.

Has the way that security credentials are passed around changed (Kerboros
seems to ring a bell)

My current thinking is that we will not be able to get app proxying across a
2003/2000 standalone servers unless we introduce a common domain, and
therefore can use the same user credentials on both com+ packages.

Does this seem likely, and does the solution seem sensible??

Regards

Craig



Relevant Pages

  • Re: Web App Security Model.
    ... SQL permissions are correctly restrictive (so worse case the allowed ... If these machines are standalone the threats posed by them are ... applications / implementation and whether their design has ... My company wants to have a few Windows Servers running web app's (ASPX ...
    (microsoft.public.security)
  • Re: Web App Security Model.
    ... If these machines are standalone the threats posed by them are ... My company wants to have a few Windows Servers running web app's (ASPX ... For the time being there wont be a Firewall between the servers and the ... so we aren't in a DMZ type environment. ...
    (microsoft.public.security)
  • AD for webhosting?
    ... Until now we have made them standalone ... IPSEC policies for some traffic and be able to apply security configuration ... But we are concerned about AD on public hosted servers. ...
    (microsoft.public.win2000.security)
  • looking for sample iptables and ipchains setups
    ... schemas - for all kinds of situtations - be they "standalone" workstations, ... servers, firewalls, routers - whatever. ...
    (comp.os.linux.security)

Quantcast