Click here to get back home

INTERACTIVE group missing after SSPI auth

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
INTERACTIVE group missing after SSPI auth Sami J. Lehtinen 10-28-2005
Posted by Sami J. Lehtinen on October 28, 2005, 12:54 pm
Please log in for more thread options
After SSPI-authentication (CompleteAuthToken() has returned
successfully) I get the user's access token by running
ImpersonateSecurityContext(), then getting the token with
OpenThreadToken(). I use DuplicateTokenEx() to make a primary token, so
I can use it with CreateProcessAsUser().

The problem I am encountering is that the access token is missing
INTERACTIVE token group. This group is required for regular users on
Windows 2003 Server to access the WINDOWS\System32 directory. Using the
access token gotten from the gss-api negotiation I cannot run cmd.exe
for the user, as I can after LogonUser().

Is it possible to add the INTERACTIVE group to the token somehow, or
otherwise instruct SSPI to give me a token with the group in there?

If no workaround is possible, can you direct me to documentation or
white-paper on this 2003 feature? If the token manipulation is
impossible, this becomes a known issue, and I'd like some formal
documentation why this has been changed in Windows 2003.

--
sjl@ssh.com


Similar ThreadsPosted
INTERACTIVE group missing after SSPI auth November 2, 2005, 3:16 pm
Group SIDs from SSPI token on Windows CE July 14, 2005, 5:39 pm
Builtin Group Missing October 11, 2005, 3:11 pm
wkstation interactive logon recorded on DC? November 16, 2005, 11:08 am
Interactive Service - Windows 2003 Server November 1, 2006, 7:25 am
Certificates 802.1X Auth. November 21, 2005, 11:07 am
NTLM Auth (weird) January 23, 2008, 4:15 pm
telnet server auth without password, how ? September 13, 2005, 4:27 pm
802.1x host auth fails with WinXP supplicant June 26, 2006, 3:41 pm
IIS prompting for password but integrated auth is only method July 10, 2006, 2:40 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap