Article ID: 176799
Article Last Modified on 2/9/2006
HKEY_CLASSES_ROOT\AppId\
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
Name Description
------------------------------------------------------------------------
None No authentication.
Connect Authentication occurs when a connection
is made to the server. Connectionless
protocols do not use this.
Call The authentication occurs when a RPC call
is accepted by the server. Connectionless
protocols do not use this.
Packet Authenticates the data on a per-packet
basis. All data is authenticated.
Packet Integrity This authenticates that the data has come
from the client, and checks that the
data has not been modified.
Packet Privacy In addition to the checks made by the other
authentication techniques, this encrypts
the packet.
Default May vary depending upon operating system.
NOTE: "Connect" and "Call" are not used for connectionless protocols. Windows NT and Windows 2000 use a connectionless protocol, UDP, by default. However, Windows 95 uses TCP, which is connection-based. Windows 95 machines can only accept calls on the "None" or "Connect" levels.
Name Description
----------------------------------------------------------------------
Anonymous The client is anonymous. This setting is
not currently supported by DCOM.
Identify The server can impersonate the client to
check permissions in the ACL (Access
Control List) but cannot access system
objects.
Impersonate The server can impersonate the client and
access system objects on the client's
behalf.
Delegate In addition to the Impersonate level, this
level can impersonate the client on calls
to other servers. This is not supported in
the current release of DCOM.
The last item on the Default Properties tab is the "Provide additional
security for reference tracking" check box, which tells the server to track
connected client applications by keeping an additional reference count.
Checking this box uses more memory and may cause COM to slow down, but it
ensures that a client application cannot kill a server process by
artificially forcing a reference count to zero.
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
Group Description
------------------------------------------------------------------------
Interactive Includes all users who log on to a Windows NT or
Windows 2000 system locally (at the console). It
does not include users who connect to Windows NT
or Windows 2000 resources across a network or are
started as a server.
Network Includes all users who connect to Windows NT or
Windows 2000 resources across a network. It does
not include those who connect through an
interactive logon.
Creator/Owner The Creator/Owner group is created for each
sharable resource in the Windows NT system. Its
membership is the set of users who either create
resource s(such as a file) and those who take
ownership of them.
Everyone All users accessing the system, whether locally,
remotely, or across the network.
System The local operating system.
The list above includes the group accounts that are intrinsic to Windows NT
and Windows 2000 systems. Your particular network may include more groups from which you may choose. In order to determine the membership of each custom group account, you must contact your network administrator.
HKEY_CLASSES_ROOT\CLSID\{...CLSID...}
Keywords: kbinfo kbdcom KB176799