Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
platform
active.directory
adsi
adsi.iis-admin
base
com_ole
complus_mts
component_svcs
database
directx
gdi
graphics_mm
internet.client
internet.server
internet.server.isapi-dev
localization
mapi
messaging
msi
mslayerforunicode
multimedia
networking
networking.ipv6
sdk_install
security
shell
telephony.tapi_2
telephony.tapi_3
telephony.tsp
telephony.wte
tools
ui
ui_shell
win_base_svcs
win16
  
 
date: Wed, 13 Feb 2008 14:02:14 -0800 (PST),    group: microsoft.public.platformsdk.internet.server.isapi-dev        back       


Defaultapppool allowing server side executables   
Our application has an executable that runs on the server.  It's on
several hundred systems and works everywhere without a problem except
this one place.  In this one place I've had to change the
defaultapppool identity from Network Service to the IWAM user.  I'm
wondering why?  I want them to all be the same so I very much want to
find out what is different with this one (Server 2003 w/iis 6).
Hoping someone can give some insight.
date: Wed, 13 Feb 2008 14:02:14 -0800 (PST)   author:   unknown

Re: Defaultapppool allowing server side executables   
On Feb 13, 2:02 pm, jfor...@amsworld.com wrote:
> Our application has an executable that runs on the server.  It's on
> several hundred systems and works everywhere without a problem except
> this one place.  In this one place I've had to change the
> defaultapppool identity from Network Service to the IWAM user.  I'm
> wondering why?  I want them to all be the same so I very much want to
> find out what is different with this one (Server 2003 w/iis 6).
> Hoping someone can give some insight.


This is not an issue with Application Pool Identity.

Look at Global Policy restrictions on privileges held by various
accounts. And compare this machine against a working machine. I bet
there is some privilege missing/denied somewhere to NetworkService or
is allowed to IWAM.

For example, someone may have an overzealous security lockdown policy
from Group Policy preventing Service logons in their domain... which
inadvertently kills Network Service and IIS. Simple changes like that
cause mysterious things like your situation all the time, and there is
little IIS or anyone can do about it. When Domain Administrator makes
a mistake in Global Policy, strange/bad things happen.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
date: Tue, 26 Feb 2008 19:19:11 -0800 (PST)   author:   David Wang

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us