Re: Do We Need DCOM Enabled?



Hey Will, I thought we had an exchange about this once in the
past. For the most part, a system functions fine without DCOM
being enabled, but you do loose some central management
capabilities (most noteably things via WMI such as in quick
scripts). Early .Net development referred to COM+ and its
remoting under the banner "Enterprise Services". DCOM is
legacy, being supplanted with native .Net remoting capabilities.
Other than loosing WMI you might notice mostly issues in
layered applications (even .Net ones which are wrappering
use of DCOM).

"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:O4idnRwV4713F1PYnZ2dnUVZ_vWtnZ2d@xxxxxxxxxxxxxxx
In order to further minimize attack surfaces, I'm thinking of

1) uninstalling "Enabled Network COM+ Access" in Add Remove Programs |
Windows Components | Application Servers

2) Starting DCOMCNFG and unselected the Enable DCOM checkbox

Which applications use either of these? When is it important to leave
DCOM enabled on a Windows 2000 and Windows 2003 server?

If you do 1) and 2), why does the DCOM Application Starter service remain
in
Automatic state, and what functions is it performing?

I read that certificate autoenrollment uses DCOM. If you have DCOM
disabled, how would you register your certificates on new servers?

If we want to develop .NET applications, does the .NET 2.0 and 3.0
architecture require DCOM?

--
Will




.



Relevant Pages

  • Do We Need DCOM Enabled?
    ... Windows Components | Application Servers ... DCOM enabled on a Windows 2000 and Windows 2003 server? ... I read that certificate autoenrollment uses DCOM. ...
    (microsoft.public.windows.server.security)
  • Error 10006 - DCOM error
    ... getting on one of my Windows 2000 servers. ... Event Source: DCOM ... DCOM got error "Class not registered " from the computer SERVER2 when ...
    (microsoft.public.windows.server.general)
  • Re: At Bootup Computer Pauses
    ... Try Ctrl+Alt+Delete to select Task Manager and click the Performance ... Also look for Error Reports in the System log in Event Viewer. ... View and Manage Event Logs in Event Viewer in Windows XP ... DCOM got an error "The service cannot be started, ...
    (microsoft.public.windowsxp.general)
  • Re: deactivating DCOM
    ... Q1 How do I enable or disable DCOM? ... "EnableDCOM" as a named value. ... setting that enables or disables incoming remote connections. ... To enable remote connections to a Windows ...
    (microsoft.public.win2000.security)
  • Re: method or property is not available because a document window is not active.
    ... permission for the COM Server application with CLSID ... particular user to open the msword instead of using the windows login ... you could set dcom or not. ... "console" and do the changes for the DCOM setting, ...
    (microsoft.public.dotnet.framework.aspnet)