{"id":1311,"date":"2014-08-29T12:06:05","date_gmt":"2014-08-29T10:06:05","guid":{"rendered":"http:\/\/hen.co.za\/blog\/?p=1311"},"modified":"2014-08-29T12:06:05","modified_gmt":"2014-08-29T10:06:05","slug":"how-to-access-the-service-controller-database-remotely-on-a-workgoup-network","status":"publish","type":"post","link":"https:\/\/hen.co.za\/blog\/2014\/08\/how-to-access-the-service-controller-database-remotely-on-a-workgoup-network\/","title":{"rendered":"How to access the &#8216;Service Controller Database&#8217; remotely on a Workgoup network"},"content":{"rendered":"<p>After having some issues with my home computers not being able to &#8216;see&#8217; each others services I started digging around for solutions &#8211; having already checked all the other possible problems. The main issue is that all these computers are running on an old fashioned &#8216;Workgroup&#8217; since I don&#8217;t have an Active Directory Controller (no Windows Servers). Thus all the machines connect using the same username\/password combination.<\/p>\n<p>I&#8217;ve made sure of things like firewalls, user accounts (as mentioned already), UAC etc. are all ok but still I got the &#8216;Cannot open Service Control Manager Database&#8217; error (Access denied (5)). I started suspecting there must be another level of security that is blocking access to view\/start\/stop Windows services across different machines. Then I stumbled across articles describing ACLs and the issue that to this day Microsoft has not exposed Service ACL&#8217;s through .Net yet (yet they have things like File and Registry ACLs exposed through System.Security namespace&#8230;).<\/p>\n<p>The only way to get to these ACL&#8217;s are through old fashioned Win32 APIs or using the SC.exe utility. I&#8217;ve read that someone wrote a C# wrapper class for these somewhere but I could not find any remaining source of this through Google. Bummer&#8230; Then using the SC.exe utility through some nasty loosely coupled integration is the only solution&#8230;<\/p>\n<p>To view the current DACL (Discretionary Access Control List) for &#8216;Service Controll Manager&#8217; you can use the followig command on the source\/host computer you want to connect to:<\/p>\n<pre>sc sdshow scmanager<\/pre>\n<p>That should give you something like this:<\/p>\n<pre>D:(A;;CC;;;AU)(A;;CCLCRPRC;;;IU)(A;;CCLCRPRC;;;SU)(A;;CCLCRPWPRC;;;SY)(A;;KA;;;BA)S:(AU;FA;KA;;;WD)(AU;OIIOFA;GA;;;WD)<\/pre>\n<p>Now, the part that was relevant to me using a &#8216;Workgroup&#8217; network is the (&#8230;AU) part because for some reason even though I&#8217;m using the same user account\/Password on all machines &#8211; and this account is an Administrator on each machine, the system only recognize the user as part of the Authenticated users group ONLY. Thus the\u00a0 (A;;CC;;;AU) part is not sufficient to allow access to the service control manager database&#8230;<\/p>\n<p>To get access to the Service Controller Database you need permissions like this: (A;;CCLCRPRC;;;AU)<\/p>\n<p>To understand what all those letters use please refer to &#8216;<a title=\"Best practices and guidance for writers of service discretionary access control lists\" href=\"http:\/\/support.microsoft.com\/kb\/914392\" target=\"_blank\">Best practices and guidance for writers of service discretionary access control lists<\/a>&#8216; which explains the whole lot. The following command can be used to &#8216;fix&#8217; the access to the &#8216;Service Controller Database&#8217;: (note that is is just an example!! Check the output of the previous command first)<\/p>\n<pre>\u00a0sc.exe sdset scmanager D:(A;;CCLCRPRC;;;AU)(A;;CCLCRPRC;;;IU)(A;;CCLCRPRC;;;SU)(A;;CCLCRPWPRC;;;SY)(A;;KA;;;BA)S:(AU;FA;KA;;;WD)(AU;OIIOFA;GA;;;WD)<\/pre>\n<p>After running this you should be able to access the\u00a0 &#8216;Service Controller Database&#8217; remotely (assuming all the other things have been checked). All good and wonderful! uhmm&#8230; Then I discover this does not display all services&#8230; bugger again..<\/p>\n<p>Actually there are two parts to the original problem &#8211; as I discovered that each Windows service on its own has an ACL that can\/should be set. Some &#8216;system&#8217; services already come with permissions for AU (Authenticated Users) so they are visible by default. Most other and particularly my custom created services don&#8217;t have the right ACLs set. To fix that is simple&#8230; Just repeat the process above for that particular service &#8211; like this (for my QuickMon 3 Service):<\/p>\n<pre>Sc sdshow \"Quickmon 3 service\"<\/pre>\n<p>This should give an output like this:<\/p>\n<pre>D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)<\/pre>\n<p>As you can see it does not have any permissions for AU. To fix access to that server you simply have to add the AU permissions like this:<\/p>\n<pre>sc.exe sdset \"Quickmon 3 service\" D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)<\/pre>\n<p>Now of course you have to repeat this for each Windows Service you need access to&#8230;<\/p>\n<p>To help in this process I created the following PowerShell script that list all Windows Servers plus their ACLs:<\/p>\n<pre class=\"brush: powershell; title: ; notranslate\" title=\"\">\r\n$services = @{}\r\nGet-Service | foreach {\r\n    $DACL = sc.exe sdshow $_.ServiceName\r\n    $service = @{\r\n        'ServiceName' = $_.ServiceName\r\n        'DisplayName' = $_.DisplayName\r\n        'ServiceType' = &#x5B;string]$_.ServiceType\r\n        'DependsOn'   = &#x5B;string]$_.ServicesDependedOn\r\n        'State'       = &#x5B;string]$_.Status\r\n        'DACL' = (&#x5B;string]$DACL).Trim()\r\n    }\r\n    $serviceObj = New-Object -TypeName PSObject -Property $service\r\n    $services.Add($_.ServiceName,$serviceObj)\r\n}\r\n$services.Values | select ServiceName, DisplayName, ServiceType, State, DependsOn, DACL | Sort-Object ServiceName\r\n<\/pre>\n<p>Now you have to repeat the whole process for each service&#8230; And that is how it&#8217;s done&#8230; Enough to keep you out of mischief or perhaps enough to get you into it again&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After having some issues with my home computers not being able to &#8216;see&#8217; each others services I started digging around for solutions &#8211; having already checked all the other possible problems. The main issue is that all these computers are &hellip;<\/p>\n<p class=\"read-more\"><a href=\"https:\/\/hen.co.za\/blog\/2014\/08\/how-to-access-the-service-controller-database-remotely-on-a-workgoup-network\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[267,16],"tags":[285,286,240,256],"class_list":["post-1311","post","type-post","status-publish","format-standard","hentry","category-administration","category-reference","tag-acl","tag-dacl","tag-powershell","tag-windows-service"],"_links":{"self":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/comments?post=1311"}],"version-history":[{"count":3,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1311\/revisions"}],"predecessor-version":[{"id":1314,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/posts\/1311\/revisions\/1314"}],"wp:attachment":[{"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/media?parent=1311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/categories?post=1311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hen.co.za\/blog\/wp-json\/wp\/v2\/tags?post=1311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}