Re: Jcifs access does not work unless the user is a local admin

Mazhar Lateef <[email protected]> Tue, 2 Feb 2016 22:47:33 -0500
Newsgroups gmane.network.samba.java
Message-ID <CAAg+8wp+F0E9fHXvnaxFvksXeE3p87eVSKii+Z15tG6AFEg=UA@mail.gmail.com>
--001a11c16e5e6ce00e052ad57aa6
Content-Type: text/plain; charset=UTF-8

Hi Michael,

Thank you for your response, much appreciate it,

I will double check the details and try again, but I do have one question,
even if I did get the credentials wrong, would they work just by simply
adding the user to the local admin group on the file server since that is
the observation that I made.

the domain used was the windows pre 2000 domain (short domain)

This was also observed at another site.

Thank you

Maz


On Tue, Feb 2, 2016 at 10:17 PM, Michael B Allen <[email protected]> wrote:

> On Sun, Jan 31, 2016 at 8:58 AM, Mazhar Lateef <[email protected]>
> wrote:
> > Hi All,
> >
> > I have a quick question I am hoping to get an answer for, so thank you
> for
> > taking the time in advance  I am trying to understand the reason for the
> > following case below.
> >
> > A user with FULL read/write permissions to a UNC path is denied access
> when
> > the data is accessed using JCIFS - The only option to make it work seems
> to
> > be by making the user a local administrator or add to the local admin
> group
> > on the target server OR IF the user has other elevated permissions on the
> > remote server/domain.
> >
> > If the user accessed the network path on windows prior to any changes in
> > permissions there is no issue with access and everything works as
> expected,
> > however if the same access is tried using JCIFS a user denied error is
> > thrown, unless the user is made a local admin or domain level access is
> > granted.
> >
> > Is this normal? and what could be the reason for this?
>
> Hi Mazhar,
>
> The user credentials are probably just wrong. Figuring out the right
> domain be deceptively easy to get wrong. Use ipconfig /all to verify
> the domain you *think* is correct for the user. Look at the domain of
> the user in the ACL. I bet $1 your domain is actually wrong in one way
> or another.
>
> Mike
>
> --
> Michael B Allen
> Java Active Directory Integration
> http://www.ioplex.com/
>

--001a11c16e5e6ce00e052ad57aa6
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div><div>Hi Michael, <br><br></div>Thank y=
ou for your response, much appreciate it, <br><br></div>I will double check=
 the details and try again, but I do have one question, even if I did get t=
he credentials wrong, would they work just by simply adding the user to the=
 local admin group on the file server since that is the observation that I =
made.<br><br></div>the domain used was the windows pre 2000 domain (short d=
omain)<br><div><br></div>This was also observed at another site.<br><br></d=
iv>Thank you<br><br></div>Maz<br><div><div><br></div></div></div><div class=
=3D"gmail_extra"><br><div class=3D"gmail_quote">On Tue, Feb 2, 2016 at 10:1=
7 PM, Michael B Allen <span dir=3D"ltr">&lt;<a href=3D"mailto:ioplex@gmail.=
com" target=3D"_blank">[email protected]</a>&gt;</span> wrote:<br><blockquot=
e class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc sol=
id;padding-left:1ex"><span class=3D"">On Sun, Jan 31, 2016 at 8:58 AM, Mazh=
ar Lateef &lt;<a href=3D"mailto:[email protected]">mazhar@virtualcod=
e.co.uk</a>&gt; wrote:<br>
&gt; Hi All,<br>
&gt;<br>
&gt; I have a quick question I am hoping to get an answer for, so thank you=
 for<br>
&gt; taking the time in advance=C2=A0 I am trying to understand the reason =
for the<br>
&gt; following case below.<br>
&gt;<br>
&gt; A user with FULL read/write permissions to a UNC path is denied access=
 when<br>
&gt; the data is accessed using JCIFS - The only option to make it work see=
ms to<br>
&gt; be by making the user a local administrator or add to the local admin =
group<br>
&gt; on the target server OR IF the user has other elevated permissions on =
the<br>
&gt; remote server/domain.<br>
&gt;<br>
&gt; If the user accessed the network path on windows prior to any changes =
in<br>
&gt; permissions there is no issue with access and everything works as expe=
cted,<br>
&gt; however if the same access is tried using JCIFS a user denied error is=
<br>
&gt; thrown, unless the user is made a local admin or domain level access i=
s<br>
&gt; granted.<br>
&gt;<br>
&gt; Is this normal? and what could be the reason for this?<br>
<br>
</span>Hi Mazhar,<br>
<br>
The user credentials are probably just wrong. Figuring out the right<br>
domain be deceptively easy to get wrong. Use ipconfig /all to verify<br>
the domain you *think* is correct for the user. Look at the domain of<br>
the user in the ACL. I bet $1 your domain is actually wrong in one way<br>
or another.<br>
<br>
Mike<br>
<span class=3D"HOEnZb"><font color=3D"#888888"><br>
--<br>
Michael B Allen<br>
Java Active Directory Integration<br>
<a href=3D"http://www.ioplex.com/" rel=3D"noreferrer" target=3D"_blank">htt=
p://www.ioplex.com/</a><br>
</font></span></blockquote></div><br></div>

--001a11c16e5e6ce00e052ad57aa6--