F
Frank1213
I have used the code sample from the KB article
http://support.microsoft.com/default.aspx/kb/248187
to impersonate a user from an ASP page and change the security context. The
impersonation works fine on Windows 2003 and XP but fails on Windows 2000.
The only way I can get impersonation to work is by enabling "Act as part of
the operating system" privileges for the IWAM_<computername> account as
mentioned in the KB article.
My question,
1. How big of a security risk is this when I deploy my application?
2. Is this an accepted security workaround?
Thanks in advance.
http://support.microsoft.com/default.aspx/kb/248187
to impersonate a user from an ASP page and change the security context. The
impersonation works fine on Windows 2003 and XP but fails on Windows 2000.
The only way I can get impersonation to work is by enabling "Act as part of
the operating system" privileges for the IWAM_<computername> account as
mentioned in the KB article.
My question,
1. How big of a security risk is this when I deploy my application?
2. Is this an accepted security workaround?
Thanks in advance.