Click here to get back home

Adding Computer account to folder security

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Adding Computer account to folder security Norman George 03-20-2006
Posted by Norman George on March 20, 2006, 9:19 am
Please log in for more thread options
Hi,

I have an IIS server that needs to access a backend SQL server database, as
well as another File folder on the same sql server. I have no problem
enabling kerberos delegation support to access the sql database using
impersonation.

However, with regard to the file folder access ( which is on the same SQL
server ) should I also add the IIS computer account to the security
permision of that File Folder as well ? Is this a proper approach?

Norman



Posted by Mark Williams on March 20, 2006, 1:11 pm
Please log in for more thread options
It seems to me that, with impersonation, you only need to make sure that the
users for which your server will impersonate have to have NTFS permissions
for them defined at the folder. You shouldn't need to add the computer
account.

--


"Norman George" wrote:

> Hi,
>
> I have an IIS server that needs to access a backend SQL server database, as
> well as another File folder on the same sql server. I have no problem
> enabling kerberos delegation support to access the sql database using
> impersonation.
>
> However, with regard to the file folder access ( which is on the same SQL
> server ) should I also add the IIS computer account to the security
> permision of that File Folder as well ? Is this a proper approach?
>
> Norman
>
>
>

Posted by Roger Abell [MVP] on March 21, 2006, 12:33 am
Please log in for more thread options
From what you have posted this cannot be answered.
You say "computer account" which to me means the machine$ account
in the domain, but you perhaps mean the IUSR_* account.
Just what identity needs access depends on the nature of the website
interface - anonymous or not and if not what types of authentication
are being used.

> Hi,
>
> I have an IIS server that needs to access a backend SQL server database,
> as well as another File folder on the same sql server. I have no problem
> enabling kerberos delegation support to access the sql database using
> impersonation.
>
> However, with regard to the file folder access ( which is on the same SQL
> server ) should I also add the IIS computer account to the security
> permision of that File Folder as well ? Is this a proper approach?
>
> Norman
>



Posted by Norman George on March 21, 2006, 8:41 am
Please log in for more thread options
Roger ,

On the IIS , we have ( on the web.config file ) enabled "Integrated
Security" and " Impersonation= true ". We are not using Anonymous. The IIS
has also been trusted for constrained delegation and only MSSQL service is
trusted.
If I need to grant access to a file folder on the same SQL , is there any
particular Service Type / SPN that need to be registered ? Someone told me
that if I just add the IIS's Computer Account ( Computer$ ) to the security
of the folder , then whoever has a local account on the IIS server , will be
granted access to the folder , and this is another alternate form of
delegation on the NTFS ?

Is this correct ?

Norman

> From what you have posted this cannot be answered.
> You say "computer account" which to me means the machine$ account
> in the domain, but you perhaps mean the IUSR_* account.
> Just what identity needs access depends on the nature of the website
> interface - anonymous or not and if not what types of authentication
> are being used.
>
>> Hi,
>>
>> I have an IIS server that needs to access a backend SQL server database,
>> as well as another File folder on the same sql server. I have no problem
>> enabling kerberos delegation support to access the sql database using
>> impersonation.
>>
>> However, with regard to the file folder access ( which is on the same SQL
>> server ) should I also add the IIS computer account to the security
>> permision of that File Folder as well ? Is this a proper approach?
>>
>> Norman
>>
>
>



Posted by Roger Abell [MVP] on March 21, 2006, 9:24 am
Please log in for more thread options
What you outline at the end is something I have not heard of before,
and it does not sound correct. The file access probably comes over
the wire as the accessing account (creds of browsing user), so the
NTFS permissions should be anticipating the end users allowed access.

> Roger ,
>
> On the IIS , we have ( on the web.config file ) enabled "Integrated
> Security" and " Impersonation= true ". We are not using Anonymous. The IIS
> has also been trusted for constrained delegation and only MSSQL service is
> trusted.
> If I need to grant access to a file folder on the same SQL , is there any
> particular Service Type / SPN that need to be registered ? Someone told me
> that if I just add the IIS's Computer Account ( Computer$ ) to the
> security of the folder , then whoever has a local account on the IIS
> server , will be granted access to the folder , and this is another
> alternate form of delegation on the NTFS ?
>
> Is this correct ?
>
> Norman
>
>> From what you have posted this cannot be answered.
>> You say "computer account" which to me means the machine$ account
>> in the domain, but you perhaps mean the IUSR_* account.
>> Just what identity needs access depends on the nature of the website
>> interface - anonymous or not and if not what types of authentication
>> are being used.
>>
>>> Hi,
>>>
>>> I have an IIS server that needs to access a backend SQL server database,
>>> as well as another File folder on the same sql server. I have no problem
>>> enabling kerberos delegation support to access the sql database using
>>> impersonation.
>>>
>>> However, with regard to the file folder access ( which is on the same
>>> SQL server ) should I also add the IIS computer account to the security
>>> permision of that File Folder as well ? Is this a proper approach?
>>>
>>> Norman
>>>
>>
>>
>
>



Similar ThreadsPosted
Excessive computer account logon/logoff loggining on security log September 12, 2006, 5:23 am
Local account home folder security win2003 June 28, 2005, 4:10 pm
Adding a Firewall Appliance - Does it give me security? June 1, 2006, 6:17 pm
Folder permissions based on computer name instead of user name June 21, 2008, 1:18 am
badPasswordTime for computer account April 5, 2006, 12:39 pm
DOMAINSEND computer account August 10, 2007, 12:37 pm
Computer Account Password November 6, 2007, 5:30 am
prevent access to shared folder when not on a domain computer July 11, 2005, 8:50 pm
Problem with Domain Computer account December 18, 2006, 2:46 pm
PCs still function on domain with computer account disabled June 14, 2006, 3:51 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap