Article ID: 255547 - Last Review: February 23, 2007 - Revision: 1.2 How To Determine If MSMQ 2.0 Servers Are Configured to Use Weakened Security for Active DirectoryThis article was previously published under Q255547 SUMMARY
Message Queuing servers that are running on Microsoft Windows 2000 domain controllers can operate using weakened security for Active Directory. If used, weakened security is enabled during installation of the first Message Queuing server on a Windows 2000 domain controller in the forest. This setting is then replicated to all other domain controllers in every domain in the forest. You should enable weakened security if any of the following operating configurations apply to your organization:
MORE INFORMATION
For users running MSMQ 1.0 on Windows NT 4.0, when the MSMQ service starts a Microsoft Remote Procedure Call (RPC) call to a Message Queuing server running on a Windows 2000 domain controller, the call is impersonated as an anonymous logon. To allow such an anonymous user access to Active Directory, domain security is weakened by not impersonating this call. Consequently, all queries for objects in Active Directory are accepted by Message Queuing servers. This means only that the properties of Message Queuing objects can be viewed; it does not mean that messages can be read (or removed) from public queues. NOTE: It is also possible to support Windows NT 4.0 users (and the other configurations discussed above) without weakening security. In this case, you must grant the Everyone group the "List Content" permission on all computer objects in each domain. This approach is considered a greater compromise of domain security, and is not recommended. To check and modify the security configuration, perform the steps below. Note that you must have previously installed the support tools that are provided in the \Support\Tools folder on the Windows 2000 distribution CD.
REFERENCES
Help for MSMQ in the Windows 2000 Online Help
| Article Translations
|

Back to the top
