Microsoft KB Archive/193168

{|
 * width="100%"|

NetShow Does Not Appear to Check File/Folder Permissions

 * }

Q193168

-

The information in this article applies to:


 * Microsoft Windows NT Server NetShow 3.0 Services

-

SYMPTOMS
When you set Publishing Point Security, and both HTTP streaming and Basic Authentication and NTLM Account Database are enabled, Microsoft Windows NT Server NetShow Services does not appear to check File or Folder permissions via the Access Control Lists (ACLs). Invalid accounts are denied access, but all valid Windows NT accounts are granted access regardless of permissions.

CAUSE
ACL checking is not enabled on the NetShow Services.

WORKAROUND

 * 1) Start the NetShow Administrator.
 * 2) On the Administrator menu, click Server Properties.
 * 3) Click the Publishing Point Security tab.
 * 4) Highlight HTTP Basic Authentication and NTLM Account Database in the list of Authentication packages, and then click Apply. The status should change to Pending. When the NetShow Unicast Service is enabled, it must be stopped and restarted before its status will change to active.
 * 5) Leave the NetShow Administrator program open and use Control Panel Services to stop and restart the NetShow Unicast Service.
 * 6) On the NetShow Administrator, click the Refresh button.
 * 7) Select the "Enable Access Control List (ACL) checking" check box to enable it. (This check box will be ghosted until the Authentication Package you select is active.)
 * 8) Click Apply.
 * 9) Set the permissions on your content as appropriate and retest.

MORE INFORMATION
NetShow Services is capable of providing authentication with or without ACL checking. If you do not enable ACL checking, NetShow Services will simply check to ensure that the credentials provided by the client match with a valid existing account. If ACL checking is not enabled and the account is valid, NetShow Services will grant access to the content. If the account is valid and ACL checking is enabled, NetShow Services will verify that the account has the proper permissions (read) on the content before streaming it. If ACL checking is enabled and the client does not have the proper security permissions, access will be denied.

Additional query words:

Keywords :

Issue type : kbprb

Technology :