#31368 - 2002-10-24 05:53 PM
RPC and Active Directory Perms
|
scottietaz
Lurker
Registered: 2002-10-23
Posts: 4
|
I'm working in a Win2K environment with Active Directory. I'm having an interesting problem. When I try to access the macro @RSERVER during a logon script of a user who doesn't have read access on the directory the script abruptly aborts. (A user with read perms on AD has no problem at all.)
I figure there is a problem with the KxRPC service and the lack of Read Perms on AD. Is there any way I can get around this constraint? I've tried list perms on AD with read on self but that doesn't work either. At the very least I would think that the script shouldn't stop all of a sudden.
|
|
Top
|
|
|
|
#31370 - 2002-10-24 09:42 PM
Re: RPC and Active Directory Perms
|
scottietaz
Lurker
Registered: 2002-10-23
Posts: 4
|
I got all the RPC stuff working for users that have read access to AD. (Read on AD = go to the root of the domain in AD users & computers and check to see if everyone or said group has "Read" security access "on this object and children objects".) We removed the default setting of Pre-Windows 2000 Compatible Access group's read privileges. We don't want just anyone to be able to read a user's attributes. So certain users can read any object in the AD domain and others can't. Those that can read -- KiXtart works great. Those that can't read -- KiXtart bombs out if I try to access
@FULLNAME @RSERVER ...and I'm not sure what else.
So this is my dilemma. I don't want to give Read access to everyone in the domain just so KiXtart runs properly.
I'm fairly sure this is a problem with the KxRPC interaction (probably the Kx95.dll from my read of article above) because I've tested with a Win95, Win98 and WinXP -- only the Win95 & Win98 machines have this problem. WinXP does just fine.
|
|
Top
|
|
|
|
#31371 - 2002-10-24 11:25 PM
Re: RPC and Active Directory Perms
|
scottietaz
Lurker
Registered: 2002-10-23
Posts: 4
|
I just found a KXRpc Event Log
Event ID: 4099 Runtime info : (Error : Access is denied. (0x5/5) GetInfo() : NetUserGetInfo on : \\MyDC failed for MyDomain\MyUser.)
|
|
Top
|
|
|
|
Moderator: Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart
|
0 registered
and 874 anonymous users online.
|
|
|