Services loose memory of logon information



Due to security on our network, we have created some in house service
applications which perform remoting database tasks to maintain security. As
such, the service runs under a special "application service account" created
for the purpose of allowing specific applications that use the service, get
at our data via the remoting technology.

Since we have upgraded servers (to Win2K3 and active directory), we are
experiencing service application logon failures when servers reboot, or the
services are manually re-started. We get Error 1069 when the login
authentication fails, however, no one has changed passwords for these
special service accounts and this can occur immediately after starting a
service. (Same day, 5 minutes later when doing a service restart.) The issue
is not 100% repeatable, that is to say, it occurs randomly, but often enough
to be a horific nuisance. If it does not happen now, it will likely happen
next reboot cycle.

Has anyone else seen the OS loose the memory of service authentication and
know any remedy. It is definitely not remembering the logon values unless
the service is running under Local System User account, which we can not do
for security reasons. The other bad part about this, is that logon failures
DO NOT go to the event log, so no one knows about it until they try to use
the programs that access these services.

Any additional information about this bug would be appreciated.

Kent



.



Relevant Pages

  • [NEWS] Advanced Application-Level OS Fingerprinting: Practical Approaches and Examples
    ... Get your security news from a reliable source. ... Dan presents an alternate approach to application-level OS fingerprinting. ... cross-platform applications which result in OS-dependant responses. ... As a part of a default Apache ...
    (Securiteam)
  • Re: Active Directory/HIPPA Question
    ... The client ... > roll out AD when their top priority this year is securing the applications ... Security is one of the biggest reasons. ... ESPECIALLY if you have 800 remote offices. ...
    (microsoft.public.win2000.general)
  • RE: New Whitepaper - "Second-order Code Injection Attacks"
    ... I make no claims that this a previously "undiscovered" security flaw. ... code injection into web applications. ... differentiate between the code injection attacks - and to explain their ...
    (Bugtraq)
  • Re: Testing MS Security Patches?
    ... >implementing MS security updates on production systems. ... be to test those applications on which your business depends. ... Download the patch. ...
    (microsoft.public.security)
  • Re: Active Directory/HIPPA Question
    ... roll out AD when their top priority this year is securing the applications ... Security is one of the biggest reasons. ... ESPECIALLY if you have 800 remote offices. ... >> I have a potential client who is mulling whether or not to invest a ton ...
    (microsoft.public.win2000.general)