serious problem running asp.net and framework on domain controller

From: Leo Muller (leo-m_at_keshet-i.com)
Date: 09/20/04


Date: Mon, 20 Sep 2004 14:41:21 +0200


I have a web server which is also the domain controller. Windows2000.
The problem is that in my application I get the error once in a while:
Failed to create file C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Temporary
ASP.NET Files\root\af32ae93\a2206a1a\pturxxyg.out.
or a similar file in the same directory.
If I give "Authenticated Users" Full Control (has to write), and restart
(!!) the IIS (thought this belonged to the past). The problem is solved.
However, this server "restores" its system NTFS security settings at
intervals. And at some stage, with the permissions gone, the same problem
will occur again.
- In the ASP.NET application I use user impersonization, but I don't know if
this is connected.
- The problem comes back all the time, obviously always at the wrong time.
- I don't know which user actually lacks the permission. I tried to find out
by trying, but this didn't help. The impersonated user is an administrator,
and the we are talking about active directory. If I would know which user
tried to make this call (I tried the user used to logon and the internet
user, to no avail), then this would help in some way.

Can anyone advise me on how to get past this problem once and for all? It
seems unrealistic that my application environment would be incompatible with
itself.

Help is very much appreciated!

Leo Muller,
Web developer



Relevant Pages

  • Re: server application unavailable
    ... You should, generally, avoid running a web server on a domain controller. ... you should create a weaker account to run the webserver as. ... So i granted it the permissions and it works. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: server application unavailable
    ... You should, generally, avoid running a web server on a domain controller. ... you should create a weaker account to run the webserver as. ... So i granted it the permissions and it works. ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: Active Directory user enumeration
    ... Domain Controller installation. ... "Permissions compatible with pre-Windows 2000 servers" ... or "Permissions compatible only with WIndows 2000 servers."/ ... allow anonymous LDAP operations other than reading the RootDSE ...
    (Pen-Test)
  • Re: How to use a Group Distribution list inorder to send and received messages
    ... In the Permissions list, locate Send As, and then click to select the ... permission of the user account that is a member of one of administrative ... groups will be reset to match the ACL of the AdminSDHolder thread. ... Directory domain controller that holds the primary domain controller ...
    (microsoft.public.exchange.admin)
  • Re: How to use a Group Distribution list inorder to send and received messages
    ... In the Permissions list, locate Send As, and then click to select the ... permission of the user account that is a member of one of administrative ... groups will be reset to match the ACL of the AdminSDHolder thread. ... Directory domain controller that holds the primary domain controller ...
    (microsoft.public.exchange.admin)