Re: Oh.... I'm just wondering who's seen this stumper...

Tech-Archive recommends: Speed Up your PC by fixing your registry



I think most of us who have been following this thread don't think the issue
is with the difference in the permissioning, but something in the code. It
just doesn't make sense that the permissions would cause the problem.
However, without a network trace that shows the actual LDAP operations being
performed and the error being returned, no one really wants to speculate any
further.

The fact that things seem to work as expected with other tools, but not with
his code seems to be a key datapoint though.

I'll just throw in that there is one other thing that might help when
checking your permissions. AD supports a constructed attribute called
allowedAttributesEffective that returns the list of attributes that the
currently bound user has rights to modify on the object in the search
result. I'm guessing this will tell you that you have delegated the
permissions exactly as you think you have, but it is always a nice sanity
check, as the AD permissioning model is so complex it is easy to get
unexpected results.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"Joe_SMS" <jw_nagy@xxxxxxxxxxx> wrote in message
news:1154268255.572453.227290@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I guess i'm wondering if I can rest assured that this is pretty much
something stupid his code is doing and not anything really to do with
permissions. I've pretty much told the world (at work) this... I just
don't have the nails for his coffin. :) Like I said, I can use his
account to read/write to any attribute he is... I've used 10 different
tools with that account to remotely add/delete values...

admod
adsiedit
ldp
aduc
adm mmc
adm web
vbscript
hyena
simplesync
ldifde

He refuses to even consider its his code. Maybe the way he's
binding....binding to one user, modifying another ? I tried NOT
binding and again, its the operation error. So until I can get him to
turn it on tomorrow and get the trace... and DSID...



.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Win2k - Account Operator not working properly
    ... You very likely have other ACL issues other than what was mentioned and I can point them out here for you for free or you can pay someone $200-500 an hour to come check it out. ... In order for that to result in inheritence protection it means the schema had to be modified. ... set the account in the GUI to inherit from its parents. ... Used the delegation wizard, on the top level OU, to assign the desired permissions. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Consider Windows XP File Security and Group Policies
    ... If you are running Windows XP and are using the NTFS file system, ... Account from being able to purge its history footprint files. ... Changing Folder permissions to Read-Execute instead of Full ... you globally apply Full Control for the Administrators group and the SYSTEM ...
    (microsoft.public.windowsxp.general)