Thanks for the tip! At least we are wiser - rebuilding the server and changing the SID for the account was a key!
David Clover ======================== IT Support Manager Maths and Computing Faculty The Open University ======================== Ext: 59367/53529 Fax: +44 (0)709 236 3568 Voicemail: +44 (0)705 069 9440 ======================== -----Original Message----- From: forrester [mailto:[EMAIL PROTECTED]] Sent: 11 March 2002 09:43 To: CF-Talk Subject: R: 401.3 Unauthorized: Unauthorized due to ACL on resource We discovered the same thing that the IUSER account had to be added otherwise you ge that message. By the way you need to be careful with asp applications. Depending on the type we have found that read access is not enough. In some cases the IUSER also needs read access to folders under \WINNT ... all part of the fun with IIS. dott. John Forrester Systems e Networking Engineer Direzione Tecnica Ancitel Spa Telefono: 0676291026 Cell Telefono: 3487972041 Fax: 0676291328 -----Messaggio originale----- Da: David Clover [mailto:[EMAIL PROTECTED]] Inviato: domenica 10 marzo 2002 16.35 A: CF-Talk Oggetto: RE: 401.3 Unauthorized: Unauthorized due to ACL on resource Though nobody offered anything on this - I've now discovered that the IUSR_servername account was not listed as a user of the z:\cfusion folders - and now I've run CACLS through the folders and added it, all is well. It's not at all clear how it happened - it may have been during a file restore after we rebuilt the server. We'd rebuilt the IUSR account too - so it had a different sid from the one stored on the backup databases which we restored. David Clover ======================== IT Support Manager Maths and Computing Faculty The Open University ======================== Ext: 59367/53529 Tel: 01908 653529 Fax: +44 (0)709 236 3568 Voicemail: +44 (0)705 069 9440 ======================== -----Original Message----- From: David Clover [mailto:[EMAIL PROTECTED]] Sent: 09 March 2002 12:44 To: '[EMAIL PROTECTED]' Subject: 401.3 Unauthorized: Unauthorized due to ACL on resource I have upgraded a server to CF 5 - it's an IIS4 server on NT 4 with the August 2001 IIS 4 security roll up installed. The NT server is running SP 6a Documents publish OK with extension .htm. I have declared the extension default.cfm, index.cfm in the IIS MMC console as valid. (see http://robots.open.ac.uk for an 'index.htm' and then see http://cci.open.ac.uk for an example failure - the .htm sidebar appears - but the .cfm body which is referenced in the frameset. See also http://computing.open.ac.uk/home/ which has an index.cfm as the root page) All documents have at least read access to account IUSR_servername. IIS4 is set up to work with anonymous access only. However, whenever I try address a document .cfm using a web browser, I receive: 401.3 Unauthorized: Unauthorized due to ACL on resource All the CF services are reported as running normally in the Service Manager. I am baffled as to where the security problem lies. Can anyone advise? The vexing part is that initially, it all worked absolutely fine. I can't even seem to get at the Cold Fusion Administrator page now. With many thanks if you can help! David Clover ======================== IT Support Manager Maths and Computing Faculty The Open University ======================== Ext: 59367/53529 Tel: 01908 653529 Fax: +44 (0)709 236 3568 Voicemail: +44 (0)705 069 9440 ======================== ______________________________________________________________________ Get Your Own Dedicated Windows 2000 Server PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation � $99/Month � Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusionb FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/[email protected]/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

