Services Login Failure



Due to security on our network, some in house service applications that
perform remoting database tasks have been created to maintain security. As
such, the service runs under a special "service account" created for the
purpose of allowing specific applications that use the service get at our
data.

Since we have upgraded servers (to Win2K3 and active directory), we are
experiencing service application login failures when servers reboot, or the
services are manually re-started. We get the expected Error 1069 when the
login authentication fails, however, no one has changed passwords for these
special service accounts and this can occur immediately after starting a
service. (Same day, 5 minutes later when doing a service restart.) The issue
is not 100% repeatable, that is to say, it occurs randomly, but often enough
to be a horific nuisance. If it does not happen now, it will likely happen
next reboot cycle.

Has anyone else seen the OS loose the memory of service authentication and
know any remedy. It is definitely not remembering the login values unless
the service is running under Local System User account, which we can not do
for security reasons. The other bad part about this, is that login failures
DO NOT go to the event log, so no one knows about it until they try to use
the programs that access these services.

Any additional information about this bug would be appreciated.

Kent


.



Relevant Pages

  • Re: Installing a Secondary Site Fails
    ... SMS can't resolve the name. ... Are you in advanced or standard security? ... a cmd prompt under the context of the SMS Service account. ... >> to grant it admin rights on secondary site server: ...
    (microsoft.public.sms.setup)
  • Re: AD User & Inherited Permissions
    ... It is the best thing for security though and I am ... You should not be using your normal user account for administrative stuff. ... and set permissions to inherit. ... We have added a mobile phone application and the Service Account needs to ...
    (microsoft.public.win2000.active_directory)
  • Re: SMS2003 Service Account Password Change
    ... You will see the SMS ... You state below that you are running your site in Advanced Security mode. ... You will read in this document that the SMS Service account is only required ... in Standard Security in SMS 2003 and not needed if you are running Advanced ...
    (microsoft.public.sms.admin)
  • Re: Using COM component in C# Web Service accessing remote network resources
    ... component being loaded from a managed component which then needs to spin up ... base security being the ASPNET account. ... security allows anonymous access using the NT service account. ... to load the configuration from the network). ...
    (microsoft.public.dotnet.security)
  • Re: Our 2000 Server was compromised and it has all the security patches.
    ... >to provide information to about new exloits, ... No possible security patch will stop that. ... passwords, auditing of login failures, firewall rules or any other of ...
    (microsoft.public.security)