Windows XP Community - XPHeads



File System ACL Required for WMI Function?

microsoft.public.windowsxp.wmi


Reply
  #1 (permalink)  
Old 04-20-2008, 07:32 PM
Will
 
Posts: n/a
File System ACL Required for WMI Function?
Something about our default security configuration for Windows 2003 and
Windows XP breaks WMI. What file system and registry ACLs are required for
WMI's proper function?

--
Will


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-06-2008, 09:01 PM
Gerry Hickman
 
Posts: n/a
Re: File System ACL Required for WMI Function?
Hi Will,

> Something about our default security configuration for Windows 2003 and
> Windows XP breaks WMI. What file system and registry ACLs are required for
> WMI's proper function?


You are asking the question back-to-front. You should KNOW the exact
changes made by your security policy and then be able to determine what
will be affected by them. Some quick checks you can do.

Log on to the Admin workstation with a Domain Admin account. Use
WBEMTEST to query a domain joined remote machine, if it fails try
disabling the firewall and try again, if it still fails, try right-click
"Computer" then "Manage", then "WMI Properties", make sure you can
access the properties, if you can't, go to the remote box and try
DCOMCNFG and make sure the computer properties are set to defaults

--
Gerry Hickman (London UK)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 05-07-2008, 05:19 PM
Will
 
Posts: n/a
Re: File System ACL Required for WMI Function?
"Gerry Hickman" <gerry666uk@newsgroup.nospam> wrote in message
news:unRUWx7rIHA.2208@TK2MSFTNGP04.phx.gbl...
> > Something about our default security configuration for Windows 2003 and
> > Windows XP breaks WMI. What file system and registry ACLs are required

for
> > WMI's proper function?

>
> You are asking the question back-to-front. You should KNOW the exact
> changes made by your security policy and then be able to determine what
> will be affected by them. Some quick checks you can do.


The conclusion does not follow from the premise. It does not follow from
the premise that you know your security policy and what it changes that you
would know the effect of any one of those changes on a particular Windows
subsystem.


> Log on to the Admin workstation with a Domain Admin account. Use
> WBEMTEST to query a domain joined remote machine, if it fails try
> disabling the firewall and try again, if it still fails, try right-click
> "Computer" then "Manage", then "WMI Properties", make sure you can
> access the properties, if you can't, go to the remote box and try
> DCOMCNFG and make sure the computer properties are set to defaults


We are not trying to use WMI on remote computers. We are getting the WMI
errors in the local eventviewer logs at startup, so something in the
subsystem doesn't appear to initialize correctly. Rather than bog down in
the detail of those messages, I was imply asking for a baseline
configuration that is known to work and the compare that against our default
settings.

--
Will


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 05-07-2008, 10:07 PM
Gerry Hickman
 
Posts: n/a
Re: File System ACL Required for WMI Function?
Will wrote:

>> You are asking the question back-to-front. You should KNOW the exact
>> changes made by your security policy and then be able to determine what
>> will be affected by them. Some quick checks you can do.

>
> The conclusion does not follow from the premise. It does not follow from
> the premise that you know your security policy and what it changes that you
> would know the effect of any one of those changes on a particular Windows
> subsystem.


Well in that case, who ever is in charge of the security policy should
be sacked for not testing it properly. Surely they'd test it against ONE
machine first, then only roll it out when it works as expected?

> We are not trying to use WMI on remote computers. We are getting the WMI
> errors in the local eventviewer logs at startup,


Well in that case, the first thing we'd need to know is the exact error.

--
Gerry Hickman (London UK)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:20 AM.








Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74