No domain is listed when changing the focus domain in the DRA web Console (NETIQKB70298)

  • 7770298
  • 17-May-2007
  • 10-Nov-2011

Environment

Directory & Resource Administrator 8.x

Situation

No domain is listed when changing the focus domain in the DRA web Console.
This only happens on remote clients if they load up the web console on the DRA server itself the domains are listed usign Integrated Authentication.

Resolution

Steps in MS Article ID 907460

Steps (run the command on every Win2k3 SP1 machine):

1. Click Start, click Run, type cmd, and then click OK.

2. Type the following command at the command prompt, and then press ENTER:

sc sdset SCMANAGER D:(A;;CCLCRPRC;;;AU)(A;;CCLCRPWPRC;;;SY)(A;;KA;;;BA)S:(AU;FA;KA;;;WD)(AU;OIIOFA;GA;;;WD)

Please note - according to Dev as far as DRA is concerned, it is sufficient if the command is run on the web server, and on the DRA server. However MS was recommended running it on every dc also.

Cause

Dev & MS tech support have confirmed that the problem is related to one MS KB article which from now on will be a 'Critical' KB article for all customers to follow: http://support.microsoft.com/kb/907460/en-us

MS documents the issue ocurring afrer Microsoft Windows Server 2003 Service Pack 1 (SP1) is installed, non-administrators cannot remotely access the Service Control Manager.

Development have confirmed that it is not a security issue but it doest affects every application which  uses these APIs through the web.

Additional Information

Formerly known as NETIQKB70298