Option to change Windows Service-Account of Gateway Service

Option to change Windows Service-Account of Gateway Service

1 vote

avatar

Hi!

Regarding Installation on a Windows Server it would be good to have a supported option to define another gateway service account than NETWORK SERVICE.

For example - session recording to SMB-Share requires authentication. It is actually possible to access a share and use it for session recording when changing the gateway service account to one that has access to that share.

But there are caveats:

  • you need to manually adept NTFS permissions for the gateway folder within "Program Data" for the new service user
  • triggering gateway update from devolutions server/RDM fails (ERROR listener{port=7171}:https{client=xx.xx.x.xxx:61728}:request{method=POST path=/jet/update}: devolutions_gateway::http: error=500 Internal Server Error at devolutions-gateway\src\api\update.rs:68:9: failed to write the new `update.json` manifest on disk [source: Access is denied. (os error 5)]))
  • everytime you modify the gateway-configuration from the server console (companion tab), the service-account automatically changes back to NETWORK SERVICE


BR

All Comments (1)

avatar

Hi!

We recognize the need for a better supported workflow here. As per internal discussions, we are looking into:

  1. Updating the installer to ensure it does not overwrite a custom service account on updates.
  2. Providing documentation about the required permissions for a custom Windows service account running the gateway.


We’ll keep you posted on any progress for official support and documentation.

Best regards,

Benoit Cortier