There are various Win32 APIs that you can use to log on a user and impersonate the account fairly painlessly available. What you can do is write a COM object which exposes a couple methods - impersonate & undo. You call impersonate, do your business, call undo - you're back to the account the script was launched as. --Brian
-----Original Message-----
From: Perdue David J Contr InDyne/Enterprise IT [mailto:[EMAIL PROTECTED]
Sent: Wed 9/1/2004 3:30 PM
To: '[EMAIL PROTECTED]'
Cc:
Subject: RE: [ActiveDir] IIS and Scripting Question
I don't know if this would work, but...
Add the share on your data server to the website as a virtual directory.
Then, add your web server's computer account or the IIS account with the access that
the app needs to your data servers share. I'm not sure which would be needed to work.
You could then use whatever your accounting mechanism is on the web server to
control access to the share.
Dave
_____
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Michael B. Smith
Sent: Wednesday, September 01, 2004 11:03 AM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] IIS and Scripting Question
No, the provisioning application needs to be able to create a folder and a
file within that folder and assign rights.
It can't be a part of the domain (our policy is that shared hosting servers
(excepting our Exchange hosting servers, which have their own domain) are standalone).
Thanks for the thought.
_____
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al
Sent: Wednesday, September 01, 2004 1:53 PM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] IIS and Scripting Question
So really the rights you need are the ability to open a file on a file share
you have rights to? Is it possible to make it part of the domain? You could use the
machine account or the IIS account then. If not, then the trick here is to allow file
system access to the application (the user-context of the application really).
Would that work?
_____
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Michael B. Smith
Sent: Wednesday, September 01, 2004 1:48 PM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] IIS and Scripting Question
I have a provisioning application that runs on a domain member that needs
administrative access to a standalone server.
_____
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al
Sent: Wednesday, September 01, 2004 1:27 PM
To: '[EMAIL PROTECTED]'
Subject: RE: [ActiveDir] IIS and Scripting Question
Credentials other than the ones that IIS is running under?
Personally, I haven't seen a way to do that and wonder why you would want to
do it that way?
_____
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Michael B. Smith
Sent: Wednesday, September 01, 2004 9:33 AM
Subject: [ActiveDir] IIS and Scripting Question
Is there any way to create a FileSystemObject with alternate credentials,
similar to what I can do with OpenDSObject for an ASP web page?
Thanks,
M
<<winmail.dat>>
