Article ID: 903220 - Last Review: October 11, 2007 - Revision: 8.5 Description of the changes to DCOM security settings after you install Windows Server 2003 Service Pack 1On This PageINTRODUCTIONMicrosoft Windows Server 2003 Service Pack 1 (SP1) introduces some
enhanced default security settings for the DCOM protocol. Specifically, Windows Server 2003 SP1
introduces rights that give an administrator independent control
over local and remote permissions for starting COM servers, activating COM server settings, and accessing COM
servers. This article describes the changes to DCOM security settings. MORE INFORMATION Windows Server 2003 certificate services uses the DCOM protocol to provide
enrollment and administration services. Certificate
services provides several DCOM interfaces to make enrollment and administration services available. For
correct access and usage of these services, certificate services assumes that
the DCOM interfaces are set to enable remote activation and access permissions.
However, because default security settings for DCOM are applied when you upgrade to Windows Server 2003 SP1, you may have to update these security
settings to make sure that enrollment and administration services are available. By default, all DCOM interfaces in Windows Server 2003 SP1 are configured to grant remote access permissions, remote launch permissions, and remote activation permissions to administrators. However, when you upgrade to Windows Server 2003 SP1, security configuration changes are made to the global DCOM interface and to the CertSrv Request DCOM interface. These changes are made to enable certificate services to work correctly. Note Any changes that have been made to the CertSrv Request DCOM interface security settings before you install Windows Server 2003 SP1 are lost. Windows Server 2003 SP1 Setup resets all previous security settings in the CertSrv Request DCOM interface to their default settings. During Windows Server 2003 SP1 Setup, certificate services automatically updates the DCOM security settings as follows:
Event message 1 Event Type: Error Event Source: AutoEnrollment Event Category: None Event ID: 13 Date: date Time: time User: N/A Computer: computer_name Description: Automatic certificate enrollment for local system failed to enroll for one Directory Email Replication certificate (0x80070005). Access is denied. For more information, see Help and Support Center at http://support.microsoft.com. Event Type: Error Event Source: AutoEnrollment Event Category: None Event ID: 13 Date: date Time: time User: N/A Computer: computer_name Description: Automatic certificate enrollment for local system failed to enroll for one Workstation Authentication certificate (0x80070005). Access is denied. For more information, see Help and Support Center at http://support.microsoft.com. The certificate request failed because of one of the following conditions: -The certificate request was submitted to a Certification Authority (CA) that is not started. -You do not have the permissions to request certificates from the available CAs. If you change the group membership to include the Domain Controllers group, you must restart the domain controller to reflect the change. Technical support for x64-based versions of Microsoft WindowsIf your hardware came with a Microsoft Windows x64 edition already installed, your hardware manufacturer provides technical support and assistance for the Windows x64 edition. In this case, your hardware manufacturer provides support because a Windows x64 edition was included with your hardware. Your hardware manufacturer might have customized the Windows x64 edition installation by using unique components. Unique components might include specific device drivers or might include optional settings to maximize the performance of the hardware. Microsoft will provide reasonable-effort assistance if you need technical help with a Windows x64 edition. However, you might have to contact your manufacturer directly. Your manufacturer is best qualified to support the software that your manufacturer installed on the hardware. If you purchased a Windows x64 edition such as a Microsoft Windows Server 2003 x64 edition separately, contact Microsoft for technical support.For product information about Microsoft Windows XP Professional x64 Edition, visit the following Microsoft Web site: http://www.microsoft.com/windowsxp/64bit/default.mspx
(http://www.microsoft.com/windowsxp/64bit/default.mspx)
For product information about x64-based versions of Microsoft Windows Server 2003, visit the following Microsoft Web site: http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx
(http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx)
For more information about the DCOM security enhancements
that are introduced by Windows Server 2003 SP1, visit the following Microsoft
Web site:http://www.microsoft.com/downloads/details.aspx?familyid=C3C26254-8CE3-46E2-B1B6-3659B92B2CDE&displaylang=en
(http://www.microsoft.com/downloads/details.aspx?familyid=C3C26254-8CE3-46E2-B1B6-3659B92B2CDE&displaylang=en)
APPLIES TO
| Article Translations
|
Back to the top
