Re: How to Stop a Service From Impersonating Other Users

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 11/27/05

  • Next message: Roger Abell [MVP]: "Re: Security log file size (Windows 2003)"
    Date: Sun, 27 Nov 2005 10:29:21 +1100
    
    

    G'day:

    "Will" <DELETE_westes@earthbroadcast.com> wrote in message

    > 1) I still don't hear a clear answer to the question of whether a service
    > needs a *password* for a given userid in order to be able to grab that
    > user's security context.

    No, it doesn't need a password.

    >From the doco
    (http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/fa01a57a-a0ef-4cb9-af9a-f30182a25bf7.mspx):

    Act as part of the operating system

    Description
    This user right allows a process to impersonate any user without
    authentication.

    -- 
    Svyatoslav Pidgorny, MS MVP - Security, MCSE
    -= F1 is the key =-
    

  • Next message: Roger Abell [MVP]: "Re: Security log file size (Windows 2003)"

    Relevant Pages

    • RE: using PerformanceCounter class in a WebMethod
      ... the impersonate may not be implemented. ... must have the "Act as part of the operating system" privilege: ... Get Secure! ...
      (microsoft.public.dotnet.framework.aspnet.webservices)
    • Re: flowing credentials through biztalk
      ... yes, they are the same, so i supose they share the same security context. ... In the orchestration I just call a helper static method that adds a custom ... Impersonate using the user windowsidentity ... Undo the impersonation to restablish the biztalk service security context ...
      (microsoft.public.biztalk.general)
    • Impersonation problem in Sharepoint 2007
      ... administrator privileges, such as create SPWebs, SPLists and ... SPS 2003, ... When we impersonate, the WindowsIdendity associated to the context ... seems that the security context on which MOSS is based, ...
      (microsoft.public.sharepoint.portalserver.development)
    • RE: Print in network printer by windows service?
      ... Regarding how to do impersonate, we can use LogonUser API to construct the ... then use ImpersonateLoggedOnUser API to lets the calling thread ... impersonate the security context of this token. ...
      (microsoft.public.win32.programmer.kernel)
    • Package Sercurity Context
      ... Under what security context does an ActiveX Script task run as if executed ... inside the DTS designer...? ... impersonate the user..? ...
      (microsoft.public.sqlserver.dts)

    Loading