Showing posts with label IIS. Show all posts
Showing posts with label IIS. Show all posts

Tuesday, August 31, 2010

Tech Notes-Changing IIS IUSR And IWAM Accounts After Server Rename


Recently I found a server which was renamed.There were two IUSR and IWAM accounts.One with the new name and one with the old one.Read on to see what you can do to get rid of old accounts and use only the new ones.
Ones you rename the machine and reboot it, you might still find the old IUSR and IWAM accounts .Now even if you delete these accounts, it will get recreated as soon as you restart IIS.Follow the below steps to get rid of the old accounts

(1) Open C:\WINDOWS\system32\inetsrv\Metabase.xml in Notepad
(2) Search for AnonymousUserName and change the value to IUSR_NEW (or any name you like) for all instance
(3) Search for WAMUserName and change the value to IWAM_NEW (or any name you like) for all instances
(4) Save Metabase.xml
(5) Start –> Run –> Services.msc –> Right click on IIS Admin Service and choose to restart.
(6)Delete the old accounts from Local Users and Groups

Now configure anonymous access with the new account in each Virtual Directory that you have created.

Friday, July 23, 2010

Tech Notes- IIS-Checking As Well As Synching Password For IUSR & IWAM Accounts


Usually the IUSR_ and IWAM_ passwords are set automatically and are never known. However, I've seen cases in which for some reason the passwords get out of sync or corrupted and need to be reset. The easiest way to reset these passwords is to extract the passwords that Microsoft IIS has in its metabase and update the accounts in Local Users and Groups to use that password.

To accomplish this you first need to update the adsutil.vbs script, which you'll find in the AdminScripts folder under the Inetpub folder, to display sensitive information (e.g., passwords) in plain text.Open the adsutil.vbs file in Notepad and search for the text "IsSecureProperty = True", replace this text with "IsSecureProperty = False" and save the file

Now run the following commands to return the passwords in plain text

/anonymoususerpass is the IUSR account
/wamuserpass is the IWAM_ account

C:\Inetpub\AdminScripts>cscript adsutil.vbs get w3svc/anonymoususerpass

Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

anonymoususerpass : (STRING) "bv6iC9d|liM)`y"


C:\Inetpub\AdminScripts>cscript adsutil.vbs get w3svc/wamuserpass

Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

wamuserpass : (STRING) "9oAFA"L8|HD2Kl"



Now you have two options.Either you can set the password for users IUSR account and IWAM_ account in Local Users and Groups same as above or if you have already set the password in Local Users and Groups set the same passwords in IIS metabase using the following commands


C:\Inetpub\AdminScripts>cscript adsutil.vbs set w3svc/anonymoususerpass "Password123"

Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

anonymoususerpass : (STRING) "Password123"


C:\Inetpub\AdminScripts>cscript adsutil.vbs set w3svc/wamuserpass "Passw0rd"
Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

wamuserpass : (STRING) "Passw0rd"



You should now run the command below to sync the password from IIS with Microsoft Transaction Server (MTS) and component services


C:\Inetpub\AdminScripts>cscript.exe synciwam.vbs -v

IIS Applications Defined:
Name, AppIsolated, Package ID


Now just reset IIS using the iisreset command


Related Posts Plugin for WordPress, Blogger...