W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch

Security Briefs

Syndication

I just got hit with this today, and a bit of googling shows that lots of folks have been running into problems with IIS6 application pools after installing SP1. My lab box is a W2K3 domain controller.

While I've been running SP1 for awhile in the lab, my app pools were running as Network Service and everything was swell. But when I switched to a custom user account, I started seeing some incredibly odd behavior.

First of all, the user account has all the right privileges - it's a member of IIS_WPG, for example. And running FILEMON shows no problems accessing files.

When the AppPool first starts up, keeping a close watch on TaskManager, I can see W3WP.EXE start up, but the user name says which is really odd. And get this - if the user account was recently created, looking at Active Directory shows that the account has *never*  been logged in. IOW, W3WP.EXE is being launched, then its dentity is being changed to the custom identity (maybe that's how IIS works, but it sure feels odd).

Looking at the security event log (I log both success and failed logon events) shows nothing. It doesn't appear as though any attempt is being made to log in the custom user (and later scouring the user account with ADSIEDIT shows that it's never been logged on). The SYSTEM event log shows about five attempts to start the application pool, then the pool is disabled (I'm sure you've seen this before). This is the typical thing you see when you get the dreaded “Service Unavailable“ error. Tip for those new to this - you need to manually restart the application pool once you get this error - refresh the Application Pools folder in IIS manager and you'll see which pools are disabled -  you need to right-click the disabled pool and choose “start“ to reenable it, otherwise you'll continue to get “Service Unavailable“ even if you've fixed the underlying problem.

The user accounts I'm using are initially created using System.DirectoryServices. I will post the steps I'm taking to create these accounts at the end of this entry. Get this - if I use the AD Users & Groups snapin to create the user instead of my own code, the IIS application pool runs just fine. I can also call net user /add to add the user (and then add it to the IIS_WPG group), and that also works just fine.

I compared the programmatically-created user account with the snapin-created account using ADSIEDIT, and only found one very small difference - an esoteric hidden flag on the account (ADS_UF_PASSWD_NOTREQD) was set on the account I created in code, but not in the snapin-created account. So I tweaked my code to turn off this switch, created a new account, and I'm still having the same problem.

As I'm writing this blog entry, I'm also installing the October security patches for W2K3 (there are oh, about 8 of them). I'm hoping that one of these patches will fix the problem.

UPDATE: After letting the bits in my VPC cool a bit after installing the patches, sure enough, the problem reappeared. And now it's not just with my programmatically created user accounts - it's happening even with user accounts I create via AD Users & Groups. Looks like it's back to the googleboard for me :(

AND SURE ENOUGH... after installing the latest security patches (just came out this week on MS Update), the problem appears to be fixed.

Well, I hope this helps somebody - writing this post gave me something to do while the new patches installed, I guess. I'll update this post if I find that I'm just hallucinating, but it does indeed look as though the problem is fixed now.


Posted Oct 14 2005, 10:41 AM by keith-brown
Filed under: ,

Comments

Michael Cuff wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 10-23-2005 6:34 PM
We are having the same issues, but only with computers with windows XP SP2 and IE6 SP2, I found the following KB article on at Microsoft and appling this sorted out our issues.

http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/f05a7c2b-36b0-4b6e-ac7c-662700081f25.mspx

Aparaschivei Constantin wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 01-10-2006 12:14 AM
I am having the same problem with windows 2003 with sp1.
Keith, did you fix the problem by installing one patch ? which one ?
Thanks.
mhz wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 09-15-2006 2:28 AM
i wonder if microsoft will do a patch for this issue since alot of ppl havin the same problem
Patrick wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 10-26-2006 4:59 AM
We had the same problem: Service unavailable
This issue occurs if you do not reinstall Windows Server 2003 SP1 after you install IIS 6.

We found the following KB article on at Microsoft. This solved our issues:
http://support.microsoft.com/kb/920720/en-us


Other useful articles:
http://www.aspforum.de/topic.asp?ARCHIVE=true&TOPIC_ID=13539
Liam wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 12-04-2006 2:21 AM
We had this problem as well. Turns out DEP was blocking the worker process from functioning due to external ISAPI provider. Needed to add the w3wp.exe to the exceptions.
Wyatt Preul wrote re: W2K3 SP1 IIS6 Service Unavailable NOT fixed with latest patch
on 12-06-2006 6:59 AM
I simply had to register aspnet and run the app pool as the local system.

aspnet_regiis -i

Also, make sure that ASPNET is allowed to run in iis
Internet Radio wrote Internet Radio
on 01-24-2009 3:20 PM

Das stimmt nicht immer, hier folgt eine aktuelle Auswahl von guten Hoster.