Access and roles in DCOM technology

Access and roles in DCOM technology

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Access and roles in DCOM technology ef 12-27-2005
Posted by =?Utf-8?B?ZWY=?= on December 27, 2005, 3:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi everybody,

I have a system consists of 4 servers. On each server there are services and
COM+ components installed. The services and components run under applicative
user. The 4 servers interact via DCOM technology. If the applicative user is
a regular user in the Domain, the DCOM operations fail because of "Access
denied". If this user is local administrator on 4 servers everything works
fine. Does anyone know, what are the minimal roles needed for the applicative
user so the DCOM technology will work between the servers? Must he be an
administrator? The operation system is Windows 2003.
Thank you in advance for any help

Efrat


Posted by Roger Abell [MVP] on December 27, 2005, 11:06 am
If you were  Registered and logged in, you could reply and use other advanced thread options
No, it is not necessary for the domain account to be an
administrator on the involved machines, and, in fact the
account should definitely not be.
It sounds like you are not taking DCom launch/access
permissions into account. These are defined on a per
COM+ component basis (when the defaults are not
sufficient), which is within the Components mmc and
which may be set for the components by the installer
during installation by an admin. Notice also that XP SP2
and W2k3 Sp1 added further DCom/Com+ security
settings (in the Security Options part of group policy)
but these should only come into play when an application
is relying on the default values (for launch/access/etc).
You would be best off adjusting the permissions that are
specific to your components - admins will be resistant to
either granting admin or over loosening for all just for the
sake of your application (or at least they should be).

> Hi everybody,
>
> I have a system consists of 4 servers. On each server there are services
> and
> COM+ components installed. The services and components run under
> applicative
> user. The 4 servers interact via DCOM technology. If the applicative user
> is
> a regular user in the Domain, the DCOM operations fail because of "Access
> denied". If this user is local administrator on 4 servers everything works
> fine. Does anyone know, what are the minimal roles needed for the
> applicative
> user so the DCOM technology will work between the servers? Must he be an
> administrator? The operation system is Windows 2003.
> Thank you in advance for any help
>
> Efrat
>



Similar ThreadsPosted
WMI / DCOM 'ACCESS DENIED' February 28, 2007, 7:29 am
Access DCOM remotly W2003 June 29, 2005, 8:53 am
DCOM - Allowing Remote Anonymous Access January 28, 2006, 7:46 pm
DCOM access denied error on Windows 2003 server SP1 January 16, 2006, 9:09 am
What Server Roles are OK to Share with a VPN? September 19, 2005, 2:30 pm
Microsoft Vista Technology November 25, 2005, 1:18 pm
Removal and forensics of advanced rootkit employing Shadow Walker technology - help needed!!! July 15, 2006, 5:24 am
DCOM February 20, 2006, 10:33 am
Disable DCOM? January 11, 2008, 1:07 pm
Dcom Exploit May 16, 2008, 2:14 pm

The site map in XML format XML site map

Contact Us | Privacy Policy