[THIN] Re: Application writing to C:\WINNT\SYSTEM32

  • From: "Gandy, Chip (COX-Atlanta)" <Chip.Gandy@xxxxxxx>
  • To: <thin@xxxxxxxxxxxxx>
  • Date: Tue, 10 Jun 2003 12:11:27 -0400

I've run into apps like this on a desktop level.  I don't flinch at
telling the vendor it has to be fixed.  It's not just a Citrix issue.
If you were to install that app on a desktop with standard access, they
would have the same issue.  So I think that you could use that as
leverage to get the vendor to fix the problem.

Immediate need, well...  that's another story. =20

EPAL - Elevated Privileges Application Launcher.  It's a tool from
Microsoft where you can assign a domain account that has local rights to
run the specified application.  That way, the users would be running
that app as an admin or even a power users and they'd have rights to it.

Microsoft Elevated Privileges Application Launcher
The Elevated Privileges Application Launcher (EPAL) tool from Microsoft
provides the ability to let an application launch under some other user
privilege, so that it has access to certain components of the local
registry or the file system. EPAL requires Active Directory for
directory based control of the feature.

Microsoft Elevated Privileges Application Launcher

http://www.microsoft.com/technet/treeview/default.asp?url=3D/technet/prod=
t
echnol/windows2000serv/downloads/epal.asp


__________________________________________=20
Chip "The Automator" Gandy=20
Systems Architect  - Systems Engineering & Data Management
Cox Communications Atlanta, MIS=20
Voice: 404-847-6039 Fax: 404-269-3010=20

First Law of Traffic:=20
The slow lane you were stopped in starts moving as soon as you leave it.


-----Original Message-----
From: Steve Rance [mailto:Steve.Rance@xxxxxxxxxxxxxxxxxxxxx]=20
Sent: Tuesday, June 10, 2003 9:28 AM
To: Thin @ Freelists (E-mail)


Hi all,

I have been given a fairly specialised application to install on our =3D
Citrix server.  After installing it on my test box I found that it =3D
creates, writes to, then deletes the file C:\WINNT\SYSTEM32\TEMP.TMP =3D
during starting up.  As a normal user doesn't have write access to this
=3D
directory the application falls over in a big heap.  If I give them Full
=3D
Access to SYSTEM32 the application works fine.  I have tried various =3D
things, including creating the file manually then giving the users full
=3D
access and dening delete, but this didn't work.

I have contacted product support and they have confirmed it is a known =
=3D
issue, however they are unlikely to fix this issue as they have very few
=3D
users (I may be the one only) that use Citrix so don't see it as =3D
problem.

I have a bad feeling about opening up Full Access to my SYSTEM32 =3D
directory on live servers.   Would you agree this is a bad thing to do?
=3D
Would you do it?

Can anyone think of a way around this issue?

I would welcome any comments on this, even if its "don't do it!" so I =
=3D
can go back to my bosses.

Thanks,

Steve

********************************************************
This weeks sponsor - Emergent Online 99Point9.com
Designed to facilitate efficient resolution of your technical
server-based questions, issues and incidents, technical support is a few
mouse-clicks away: you submit your incident-specific support requests
via our online support helpdesk, our certified engineers resolve them
while you monitor the progress, and your systems get back to 99.9%
up-time in no time.
http://www.99point9.com=20
**********************************************************
Useful Thin Client Computing Links are available at:
http://thethin.net/links.cfm

For Archives, to Unsubscribe, Subscribe or=20
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm

********************************************************
This weeks sponsor - Emergent Online 99Point9.com
Designed to facilitate efficient resolution of your technical server-based 
questions, issues and incidents, technical support is a few mouse-clicks away: 
you submit your incident-specific support requests via our online support 
helpdesk, our certified engineers resolve them while you monitor the progress, 
and your systems get back to 99.9% up-time in no time.
http://www.99point9.com 
**********************************************************
Useful Thin Client Computing Links are available at:
http://thethin.net/links.cfm

For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
http://thethin.net/citrixlist.cfm

Other related posts: