Click here to get back home

DCOM access denied after SP1 applied

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
DCOM access denied after SP1 applied ncfitton 01-06-2006
Posted by ncfitton on January 6, 2006, 3:46 pm
Please log in for more thread options
I have an acquisition application (APP) running on a Windows 2000 computer
sending data to a DCOM database application (DBAPP) on a Server 2003
computer.

Prior to SP1 on the server, the APP was able to connect to DBAPP without the
user having any special priveleges on either computer. After SP1, the APP is
no longer able to connect and gets the error RPC_E_ACCESS_DENIED.

Assuming this problem is created by a security hole being closed. I am not a
Server 2003 expert. Any suggestions on how open the access back up?

Posted by Roger Abell [MVP] on January 7, 2006, 12:02 am
Please log in for more thread options
The first thing you should do is check with the vendor of the application.
SP1 for W2k3 implemented tightened control on DCOM component launch
and access if the component is relying on default permissions (as opposed
to its having specified component specific permissions).
Since this change was first introduced much earlier during the beta cycle
for XP SP2 it is likely the vendor has faced the issue already, so there
may be no need for you to reinvent the wheel.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

>I have an acquisition application (APP) running on a Windows 2000 computer
> sending data to a DCOM database application (DBAPP) on a Server 2003
> computer.
>
> Prior to SP1 on the server, the APP was able to connect to DBAPP without
> the
> user having any special priveleges on either computer. After SP1, the APP
> is
> no longer able to connect and gets the error RPC_E_ACCESS_DENIED.
>
> Assuming this problem is created by a security hole being closed. I am not
> a
> Server 2003 expert. Any suggestions on how open the access back up?



Posted by ncfitton on January 7, 2006, 3:03 pm
Please log in for more thread options
Hi Roger,
Thanks for the response. Unfortunately, I am the vendor :-) I have 3
customers with the problem but the product is no longer in development and I
am not familiar with the code.

Yesterday I read the SP1 release notes in detail and I am confident that the
changes to DCOM and certificate services are the culprit. What I don't get
yet is do I:
1. add the non-adminstrative users to the new DCOM Remote users group
created by SP1
2. change the computerwide DCOM access rights through
MMC/Computer/Properties/COM Settings
3. Create an ACL that grants everybody launch and access to the DCOM
application on the server.

or some combination of the above. Items 1 & 3 i do not know how to do yet.

Any more help appreciated. Nick.

"Roger Abell [MVP]" wrote:

> The first thing you should do is check with the vendor of the application.
> SP1 for W2k3 implemented tightened control on DCOM component launch
> and access if the component is relying on default permissions (as opposed
> to its having specified component specific permissions).
> Since this change was first introduced much earlier during the beta cycle
> for XP SP2 it is likely the vendor has faced the issue already, so there
> may be no need for you to reinvent the wheel.
>
> --
> Roger Abell
> Microsoft MVP (Windows Server : Security)
>


Posted by Roger Abell [MVP] on January 8, 2006, 11:24 am
Please log in for more thread options
Try 3 and if these are domain accounts or explicitly stated local accounts
being used then 1 applies
Use of 2 is a last resort and whould for me rule out your application
as an allowed installable.

> Hi Roger,
> Thanks for the response. Unfortunately, I am the vendor :-) I have 3
> customers with the problem but the product is no longer in development and
> I
> am not familiar with the code.
>
> Yesterday I read the SP1 release notes in detail and I am confident that
> the
> changes to DCOM and certificate services are the culprit. What I don't get
> yet is do I:
> 1. add the non-adminstrative users to the new DCOM Remote users group
> created by SP1
> 2. change the computerwide DCOM access rights through
> MMC/Computer/Properties/COM Settings
> 3. Create an ACL that grants everybody launch and access to the DCOM
> application on the server.
>
> or some combination of the above. Items 1 & 3 i do not know how to do yet.
>
> Any more help appreciated. Nick.
>
> "Roger Abell [MVP]" wrote:
>
>> The first thing you should do is check with the vendor of the
>> application.
>> SP1 for W2k3 implemented tightened control on DCOM component launch
>> and access if the component is relying on default permissions (as opposed
>> to its having specified component specific permissions).
>> Since this change was first introduced much earlier during the beta cycle
>> for XP SP2 it is likely the vendor has faced the issue already, so there
>> may be no need for you to reinvent the wheel.
>>
>> --
>> Roger Abell
>> Microsoft MVP (Windows Server : Security)
>>
>



Posted by ncfitton on January 9, 2006, 5:43 pm
Please log in for more thread options
I ended up with a slight variation.

1. I added all the required domain users to the Distributed COM Users group
that was created by SP1.

2. Instead of opening up the entire computer to those users, you can choose
the particular DCOM app and elevate users to have both local and remote
launch, activation and access rights. Actually I tried this last year but
without Step 1 it doesn't work.

I did all of this through the dcomcnfg console.

Thanks Roger.

Nick.

"Roger Abell [MVP]" wrote:

> Try 3 and if these are domain accounts or explicitly stated local accounts
> being used then 1 applies
> Use of 2 is a last resort and whould for me rule out your application
> as an allowed installable.
>


Similar ThreadsPosted
DCOM access denied error on Windows 2003 server SP1 January 13, 2006, 10:35 am
Getting Access is Denied March 2, 2006, 6:30 pm
DRA and access denied September 28, 2006, 10:13 am
Everybody denied access to a folder June 19, 2006, 4:52 am
Access XP Permission Denied July 12, 2006, 9:52 pm
CDROM Drive access denied October 31, 2005, 10:40 am
Certificate services Access Denied November 9, 2005, 9:02 pm
Access denied to event viewer? December 22, 2005, 4:07 pm
Event Viewer Access Denied January 27, 2006, 12:37 pm
EnumPrinters(PRINTER_ENUM_NAME) = Access Is Denied September 25, 2006, 10:20 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap