delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2008/11/21/05:31:17

X-Recipient: archive-cygwin AT delorie DOT com
X-Spam-Check-By: sourceware.org
Date: Fri, 21 Nov 2008 11:31:27 +0100
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: cygwin AT cygwin DOT com
Subject: Re: Run OpenSSH service with Local System Account
Message-ID: <20081121103127.GD2982@calimero.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
References: <b85eaed70811201537w76b76afbmab523c28c07182ab AT mail DOT gmail DOT com>
MIME-Version: 1.0
In-Reply-To: <b85eaed70811201537w76b76afbmab523c28c07182ab@mail.gmail.com>
User-Agent: Mutt/1.5.16 (2007-06-09)
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

On Nov 20 15:37, William Zhang wrote:
> Hi All,
> 
> Sorry i hit the send button by mistake before I finished the last
> mail. This is my
> full question.
> 
> I am wondering if there is a way to run the Cygwin OpenSSH service as
> Local System Account in Windows 2003 and 2008 instead of the
> cyg_server account created during the setup.   I am using
> Cygwin+OpenSSH on the Windows test server and I remotely execute
> automation testing script from a linux box. However the program

This won't work.  The reason why you can't use the LocalSystem account
to run sshd (*and* get pubkey authentication) is not a Cygwin
restriction, but a Windows restriction.  With Windows 2008 this works
even worse because the "Interact with desktop" has been officially
deprecated for security reasons.  It's still available in the services
GUI but it doesn't work as on earlier systems.

There are probably other workarounds for your problem.  What exactly
are you testing?  Why do you need interaction with the desktop, even
though you're doing automated script testing?

For instance, the official workaround as propagated by Microsoft is to
start the application by the user account running the desktop session
and to use IPC mechanisms (named pipes, sockets) to communicate between
the service and the desktop application.


Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader          cygwin AT cygwin DOT com
Red Hat

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019