ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Cache an IIS security token in Windows 2000 Server

Jim Boyce

Published: 26 Jun 2006 11:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security in Windows 2000 Server is based on tokens. When you log on, the operating system creates a token for you that contains all the security identifiers (SIDs) for the groups you belong to and your privileges. Whenever you try to access a resource, the operating system checks your token and the ACL on the resource to determine if you're allowed to access that resource.

By default, Internet Information Services (IIS) caches the token and waits 15 minutes before updating. This delay can cause a problem in some situations, such as after changing passwords. You have two options for eliminating this wait: One, stop and start all IIS services. Or two, change the default update interval, which you can do through a registry edit.

To change IIS's default update interval, first open the Registry Editor (Regedt32.exe) and go to registry key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\InetInfo\Parameters

Then,

  1. On the Edit menu, click Add Value, type "UserTokenTTL" in the Value Name text box, and select REG_DWORD as the Data Type.
  2. In the Data box, type the number of seconds for the token to be cached. (For Windows 2000 IIS5 the minimum is 1 second.)
  3. Close the Registry Editor and then stop and restart all IIS services.

For performance reasons, be careful not to set the UserTokenTTL value too low. If you make updates infrequently, use the stop-restart method mentioned in paragraph two, above.

Note: Editing the registry can be risky, so be sure you have a verified backup before making any changes.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
80 out of 134 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Peoplesoft Team Leader

Strategic Resource Group Limited acts as an Employment Agency and an Employment Business) You will join an ongoing implementation and therefor need ...

Sky

Self motivator - energy and drive for continuous improvement, focused on delivering results - Ablility to think outside of the box, generate ...

CRM Incentive Compensation Management Consultants-00047339

Solution Architecting working across customer and delivery teams to define a robust technical solution that can deliver value within time/resource ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.