IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old September 8th, 2006, 09:34 AM
djinn1 djinn1 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2006
Posts: 1 djinn1 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 24 m 9 sec
Reputation Power: 0
Identity: impersonate=True? Privlege missing?

This deals with .NET and IIS.

This issue has to do with security when accessing a web service anonymously and trying to write to appliication event log.

**** <identity impersonate="true" />
IIS anonymous account = domain\ProxyAccount

With the above setting when trying to write to the application event log I receive:
Source: security
Catagory: Privilege Use
Type: Failure Audit
Event Id: 578
Privileges: SeBackupPrivilege
User: ProxyAccount

I understand that SeBackupPrivilege is required by the RegSaveKey and RegSaveKeyExfunctions.

The thing I don't understand is when I use the following which is to hardcode the userName and password into the web.config I no longer see this error.

**** <identity impersonate="true" userName="domain\ProxyAccount" password="WhatEver" />


The goal is not to hardcode the username and password.
I have to get an explanation for management why using the domain account when not hardcoding it (impersonate="true": using the anonymous IIS) does not allow writing to the event log but when hardcoding the same domain account it does allow writing to the event log.
the "domain\ProxyAccount" does have the correct permissions on the server to write to the Event Log (file and registry).

I don't know but it seems like the hardcoded account gets the correct/all of the permissions and privleges but when impersonating the IIS anonymous account it does not.


Is there any articles on this that I am missing. I have been researching this and not finding a concrete explaination of why.

Also is there a fix for this issue.

Thanks!!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Identity: impersonate=True? Privlege missing?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway
Stay green...Green IT