Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Access denied error while using webservice
GBS
Hi,
I get the following error while trying to create a workspace using the sample webservice in Worksite SDK 8.0:
"The request failed with HTTP status 401: [NRTSession] [TrustedLogin] Access denied".
If any of you have come across this problem and know the solution please let me know.
Thanks,
GBS.
Find more posts tagged with
Comments
jny
The fix to this is in the WorkSite Web 8.0 HF1 which is due out in two weeks or so.
dmdejong
Is there any way to do a trusted login using the 7.5 SDK? I'm getting the same issue even though the Impersonation and everything is setup properly.
jny
You should be able to do trusted login in 7.5 if you have added your windows domain accounts to the database via DBAdmin program. I'm not sure how it ties to impersonation setup that you have mentioned though...could you explain further?
dmdejong
I think I've found the problem. Since the DLL is single-threaded (STA) you can't do impersonation from the .NET web services. In regular ASP.NET you could use the ASPCOMPAT option but this isn't available in web services (although it may be in Whidbey). Check out:
http://support.microsoft.com/default.aspx?scid=kb;en-us;325791
I have been able to do TrustedLogin using this technique but controlling your own threads and thread pools seems like a lot of work!
It would be great if Interwoven would provide an updated DLL which calls the CoImpersonateClient() function (as an option) during the TrustedLogin method. I think that would be the only place you need it. Is that what they are having such trouble with in the 8.0 SDK?
jny
The imanage.dll that is distributed with the SDK has always been STA up untill version 8.0. In the SDK 8.0, the DLL is both threaded. If you have 7.5 and have 4.X WorkSite Web, you should be able to use the DLL in the Web product as it is both threaded.
dmdejong
Well, I've got the DLL which is marked "This build targeted at servers - BOTH Threading" but it makes no difference. It is still Apartment model so I think the web service still makes an STA call and therefore there is no impersonation. I think the only solution is to have iManage.dll customized to do the CoImpersonate call inside TrustedLogin().
dmdejong
I may have spoken too soon! I did an IIS restart and I think it is hitting the new DLL now. If you don't hear back from me this solution works!
dmdejong
Trouble again. Everything was working on a single machine but I have moved the web service to a separate server now. It does not give an error on the trusted login (Acces denied, etc.) but it is NOT connected after the call to TrustedLogin. I have verified the impersonation by having the web service return HttpContex.Current.User.Identity.Name and it is correct.
Also, does the iManage.dll have any dependencies?
Any help would be apprecicated!
dmdejong
I believe this is some kind of delegation limitation. If I use a fixed identity (e.g. <identity impersonate=true userName='' password=''> everything works beautifully. I think this is because the delegation is implicit. If I resort back to impersonation the TrustedLogin() method is executed but the Session is not Connected. So... I'm not sure if this has anything to do with the .Net <-> COM limitations or it is because we are using NTLM in a Windows 2000 Mixed domain. Anybody have any experience with this?