Groups | Blog | Home
all groups > iis security > october 2005 >

iis security : IUSER on Cluster


LionPaw
10/13/2005 9:19:09 PM
Running an active/passive cluster with a shared drive cluster resource S that
holds the web sites pages.
When Server 1 is serving pages IUSer_Server1 runs the site
When The cluster rolls and Server 2 is serving the pages IUSER_Server2 is
used.

THe trouble is that the ACLS on the Shared S Drive will only resolve the SID
of the IUSER account whoes server is active. So if Server One is running,
the S Drive shows Unresolved SID for the IUSER_Server2 Account. When it
rolls the revers is True.

It works, I just dont like having unresolved SIDS. Would a Domain account
for both servers IUSER accounts be the answer or be more trouble? could it
be locked out?

Appreciate any suggestions.
Thanks
--
Doug Deitterick
10/14/2005 3:19:37 PM
That's what we did and it works just fine. We created a domain account with
a really strong password and use 1 account for all our public web.

--
Doug Deitterick
Systems Administrator
Pennsylvania College of Technology
One College Avenue
Williamsport, PA 17701
ddeitter@pct.edu
[quoted text, click to view]

Tom Kaminski [MVP]
10/14/2005 3:28:12 PM
[quoted text, click to view]

Same here. A domain account works well for IUSR.

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsserver2003/community/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS

LionPaw
10/15/2005 1:05:02 PM
Thanks for the confidence.

No concerns of account lockout? We have a policy to lockout for 15 min
after several bad attempts. Would that mean the web server stop being able
to show thos pages?

Thanks
--
PSU Guy


[quoted text, click to view]
Tom Kaminski [MVP]
10/17/2005 8:52:02 AM
[quoted text, click to view]

Sure, could be a concern. Use a name that anyone is unlikely to guess.

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsserver2003/community/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS

Chris Cichocki
11/8/2005 10:36:14 AM
Isn't another option synchronizing the IUSR names and passwords on all nodes
in the cluster? It's relatively easy to do and I would think it would work
just fine.

Chris

[quoted text, click to view]
AddThis Social Bookmark Button