Re: Service running as Local system account Unable to map drive on




Hi Joe and Phillip

Thanks for the information and input.

To answer your initial question Joe: Yes i have made sure that the computer
account has full permissions on both the share and the file system itself.
But to no awail, as i still not have been able to access the share.

You mention that Kerberos auth is used when computer accounts are used to
grant permissions. Can it be some setting in there that i need to tweak or
something (i have left the settings to their default values)?

Another thing which puzzels me is that i have noticed the following in the
Security Eventlog:

There are no errors in the Eventlog (on neither of the machines), but the
failed attemp to access the share results in a entry saying that the User
Anonymous Logon has been granted "SeChangeNotifyPrivilege" (and only that
privilege)

I have made sure that the security setting "Additional restrictions for
anonymous connesctions" is set to "None, rely on default", but was wondering
whether there could be other settings which need to be changed?

By the way, i have modified the code in my app, to use the LogonUser() and
ImpersonateLoggedOnUser() functions to run as another user with success (been
able to create files in the share), so the error is not in some other parts
of the code. But this solution is not my first choice so i would prefer to
get the other method working.

Thanks for all your help, and have a happy New Year all

Kind regards/ Venlig hilsen

Peter Langhoff Feddersen
System Engineer, MCSD

Systematic Software Engineering A/S
Web: www.systematic.dk





"Joe Richards [MVP]" wrote:

> The most common use I have deployed them for in companies is for software
> installation shares for apps that aren't security critical and it doesn't matter
> who sees the installation packages.
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> Phillip Windell wrote:
> > "Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
> > news:uK8aEF1CGHA.2644@xxxxxxxxxxxxxxxxxxxxxxx
> >> If kerberos auth is being used, you simply grant rights for the computer
> > account
> >> from AD on the share and the file system. The security concern is that
> > ANYTHING
> >> running as localsystem on the specific computer will have access to the
> > share.
> >
> > Ok, that makes sense.
> >
> >> For anonymous access you enable the null session share and set the ACL on
> > the
> >
> > This is the first time I have seen the term "null session share",...I've
> > never heard of it.
> >
>
.



Relevant Pages

  • cannot delete programmes
    ... and examine the properties on the security tab. ... If you are running with the FAT file system, ... account has on the file. ... If the file is currently running, the error message will ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Determine AD group membership
    ... If you are only interested in the security groups that a user would have in ... What Joe was trying to suggest though is that the user may be in many more ... list of groups an AD account (the one who has already logged onto the ... the account has been assigned membership. ...
    (microsoft.public.platformsdk.security)
  • Risks Digest 25.73
    ... German electronic health card system failure ... Risks of the Cloud: Liquid Motors ... Oakland 2010, IEEE Symposium on Security and Privacy, CFP ... A friend's facebook account was hacked recently (a neat little short-term ...
    (comp.risks)
  • Re: MBSA, Office Update, Versions, Failures
    ... I apologize for posting this to three groups (MBSA, Windows Update, ... with Domain User account. ... Microsoft Baseline Security Advisor (? ... Office 2000 Security Patches - Red X's, ...
    (microsoft.public.officeupdate)
  • Re: write with cURL
    ... you can stop making excuses. ... up an account for you, process the billing, etc. ... possible features from a web site to make up for the security issues. ... Nothing you have told me shows me you know how to lock down a server ...
    (alt.php)