Article ID: 184702
Article Last Modified on 9/23/2003
APPLIES TO
- Microsoft Remote Data Services 2.1
- Microsoft Remote Data Services 1.5
- Remote Data Service for ADO 2.0
This article was previously published under Q184702
SYMPTOMS
When using Remote Data Service (RDS) to call a local or
remote COM server, the server only recognizes the first caller into the object.
If subsequent calls are made to the object by different clients, the server
only impersonates them as the initial caller. This behavior has some far
reaching side effects that can cause serious security problems. For example, it
renders the Microsoft Transaction Server (MTS) role based security model
unusable with RDS. It also causes the MTS ISecurityProperty interfaces to
return incorrect information.
The Windows NT 4.0 Service Pack 4
(SP4) changes the behavior slightly. When the service pack is installed on a
computer, the caller will be seen as the process identity if the MTS package is
set to run as a server process on the same computer as the Internet Information
Server (IIS). In most cases the identity will be that of the system account
(NT_AUTHORITY\SYSTEM).
CAUSE
This is a limitation of COM on the current Windows
platforms. COM does not support clients that impersonate many different users
such as IIS. The problem is that for performance reasons, COM caches remote
procedure call (RPC) connections. In doing so, it also caches authentication
information. This caching causes COM security to incorrectly report identities
if the client impersonates many different users.
The behavior in
Windows NT 4.0 was to simply show the identity of the first caller for the
duration of the connection. Because the connections timeout after a period of
two minutes of inactivity, you could see a somewhat random identity at the
server.
To partially correct this in sp4, the COM behavior was
changed to always report the process identity for local calls. Remote calls
behave the same. While far from optimal, it at least allows the server to
reliably obtain some client identity.
STATUS
Microsoft has confirmed that this is a bug in the Microsoft
products that are listed at the beginning of this article.
This bug has been fixed in Microsoft Data
Access Components 2.1 Service Pack 2 and later.
You can download the
latest version of the Microsoft Data Access Components from the following site:
It is recommended that you download and install the latest
version of MDAC to resolve this issue. However, a hotfix is available for RDS
2.1 calling MTS 2.0 components. Please contact Microsoft Product Support for
more information on this hotfix.
Keywords: kbbug kbfix kbmdacnosweep KB184702