Security - Data Source Setting - lock application

Security - Data Source Setting - lock application

avatar

Hello!

After some testing I ran into a security issue.
I work with two users - a normal user without Administrator permission in RDM and an administrator account - also in RDM.
In the data source settings of RDM we activated "Force application security with Windows credentials".

On a testmachine I am logged in with the administrator account and want to start RDM with my normal user. If I start RDM now and enter my normal user RDM gets started in the context of administrator.

Best Regards,
Andy

All Comments (9)

avatar

Hello,

What mechanism are you using to start the app as another user?

The credentials you are prompted for are for the data source, so when you say that RDM gets started in the context of administrator what symptoms are occurring? What are you achieving that you feel you shouldn't be able to?

Thank you

Maurice

avatar

Ok to be a little bit more specific - I am logged into windows with xag2 (the admin account)
I only double click the icon on the desktop and when the logon prompt appears I enter my normal user ag.

Now I see all entries in the datasource altough for ag not all entries are visible.
I am able to change data source settings, users, security groups, roles etc. what only should be able for the administrator.
If I create a new entry or delete one in the logging I can see that I am doing it in the name of xag2.
If I click on Help -> About I can see Current user: xag2

As data source we use SQL Server.

For me it looks like RDM is started in the user context which is logged on to system and the application start security only authenticates to SQL Server!?

Best regards,
Andy

avatar

Please use File-My Data source information and use the envelope button to send us the info.

Thank you

Maurice

avatar

Done!

avatar

Hi andybandy,

We have not received your File -> My Data Source Information report. Could you please send it again.

Thank you

Jeff Dagenais

avatar

Hello!

Tried again to send it. I got the message that it was sent.

Best regards,
Andy

avatar

Hello,

This is a scenario that I cover daily in my demos, my windows account is domain admin, my data source is registered with a plain user and in consequence the Administration tab has mostly greyed out buttons.

Could I connect to your system to have a peek?

Thank you

Maurice

avatar

Hello Maurice,

yes this would be possible. Just give me your Email-Address to send you my contact data.

avatar

For us this issue is solved because we will start using Remote Desktop Manager Server as datasource.