Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: Authentication: NT
 Snitz fails after removing "Everyone" from pre-Win
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

tiffster
Starting Member

6 Posts

Posted - 26 August 2002 :  15:37:45  Show Profile
Version 3.3.03
Database: SQL 2000

After following Microsoft's advice (and the advice of security experts), we removed "Everyone" from Pre-Windows 2000 Compatible Access in Active directory. This caused the Snitz application to fail with an "internal server error 500".

Subsequent debugging isolated the problem to the following line in the NTAuthenticate() subroutine in the inc_functions.asp file:

Set strNTUserInfo = GetObject("WinNT://"+strNTUser)

IIS is unable to make this call if anonymous access is removed as described above, and therefore we must choose between a secure infrastructure or a functional Snitz application.

Ideas?

Nikkol
Forum Moderator

USA
6907 Posts

Posted - 26 August 2002 :  17:58:25  Show Profile
What was the specific error? Syntax? Object not found?

Nikkol ~ Help Us Help You | ReadMe | 3.4.03 fixes | security fixes ~
Go to Top of Page

tiffster
Starting Member

6 Posts

Posted - 27 August 2002 :  09:44:37  Show Profile
For clarification - we received this error when the GetObject function attempted to instantiate the WinNT object in this code:
Set strNTUserInfo = GetObject("WinNT://"+strNTUser)

A little more info for you...we went from a Mixed domain to a Native Domain and removed "everyone" from the permissions. It is our opinion that Snitz would not have been successful if we would have started out in Native domain.


Edited by - tiffster on 27 August 2002 14:15:24
Go to Top of Page

Nikkol
Forum Moderator

USA
6907 Posts

Posted - 27 August 2002 :  17:35:41  Show Profile
You still haven't said exactly what error. The only error you have said is internal server error, which if you turn off 'show friendly error messages' in IE, you will get the VBScript error code and description.

Nikkol ~ Help Us Help You | ReadMe | 3.4.03 fixes | security fixes ~
Go to Top of Page

ajhvdb
Junior Member

Netherlands
392 Posts

Posted - 27 August 2002 :  18:03:28  Show Profile
You can remove everyone but the IIS user IUSR_??? must have permissions to get to this data

Edited by - ajhvdb on 27 August 2002 18:04:09
Go to Top of Page

Kal Corp
Average Member

USA
878 Posts

Posted - 27 August 2002 :  23:56:33  Show Profile  Visit Kal Corp's Homepage
By default is not the IUSR_XXXX account placed into the guest group? and that had same access as members in the users group. Except for the guest account which has further restrictions.

My job is a very big MS site and one of the bigest MS-SMS sites. They still have Everyone

If you removed "everyone" then you might have to find the account the server is using to get the info from the domain and set it up so it has access.


{VAS}-Kal Corp
VAS Development NetWork - Forums for old Snitz Mods!
Creator of all things {VAS}
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.13 seconds. Powered By: Snitz Forums 2000 Version 3.4.07