【问题标题】:How to allow IIS APPPOOL\DefaultAppPool to write into C:\inetpub\wwwroot mount point如何允许 IIS APPPOOL\DefaultAppPool 写入 C:\inetpub\wwwroot 挂载点
【发布时间】:2019-06-15 22:16:53
【问题描述】:

我正在创建一个新的 Windows docker compose,它使用 microsoft/aspnet:4.6.2 图像。我正在为 c:\inetpub\wwwroot 使用一个卷,该卷与主机服务器上的 C:\site\Default 映射。

正在运行的 ASP.Net 文件成功检索文件,但在创建/写入文件时检索文件。我收到以下异常:System.IO.IOException: 'Trying to write to forbidden path: C:\inetpub\WWWRoot\agenda.css.'

我尝试了以下方法:

  • 在主机服务器上为所有人设置对 C:\site\Default 的完全访问权限

  • 使用 icacls 添加所有权限(请参阅下面的 dockerfile)。这是(Get-acl c:\inetpub\wwwroot\).Access 的输出:

    FileSystemRights  : FullControl
    AccessControlType : Allow
    IdentityReference : Everyone
    IsInherited       : False
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : None
    
    FileSystemRights  : ReadAndExecute, Synchronize
    AccessControlType : Allow
    IdentityReference : BUILTIN\IIS_IUSRS
    IsInherited       : False
    InheritanceFlags  : None
    PropagationFlags  : None
    
    FileSystemRights  : -1610612736
    AccessControlType : Allow
    IdentityReference : BUILTIN\IIS_IUSRS
    IsInherited       : False
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
    FileSystemRights  : FullControl
    AccessControlType : Allow
    IdentityReference : IIS APPPOOL\DefaultAppPool
    IsInherited       : False
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : None
    
    FileSystemRights  : FullControl
    AccessControlType : Allow
    IdentityReference : NT SERVICE\TrustedInstaller
    IsInherited       : True
    InheritanceFlags  : None
    PropagationFlags  : None
    
    FileSystemRights  : 268435456
    AccessControlType : Allow
    IdentityReference : NT SERVICE\TrustedInstaller
    IsInherited       : True
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
    FileSystemRights  : FullControl
    AccessControlType : Allow
    IdentityReference : NT AUTHORITY\SYSTEM
    IsInherited       : True
    InheritanceFlags  : None
    PropagationFlags  : None
    
    FileSystemRights  : 268435456
    AccessControlType : Allow
    IdentityReference : NT AUTHORITY\SYSTEM
    IsInherited       : True
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
    FileSystemRights  : FullControl
    AccessControlType : Allow
    IdentityReference : BUILTIN\Administrators
    IsInherited       : True
    InheritanceFlags  : None
    PropagationFlags  : None
    
    FileSystemRights  : 268435456
    AccessControlType : Allow
    IdentityReference : BUILTIN\Administrators
    IsInherited       : True
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
    FileSystemRights  : ReadAndExecute, Synchronize
    AccessControlType : Allow
    IdentityReference : BUILTIN\Users
    IsInherited       : True
    InheritanceFlags  : None
    PropagationFlags  : None
    
    FileSystemRights  : -1610612736
    AccessControlType : Allow
    IdentityReference : BUILTIN\Users
    IsInherited       : True
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
    FileSystemRights  : 268435456
    AccessControlType : Allow
    IdentityReference : CREATOR OWNER
    IsInherited       : True
    InheritanceFlags  : ContainerInherit, ObjectInherit
    PropagationFlags  : InheritOnly
    
  • 我在主机服务器上使用了 ProcMon,但在尝试写入文件时看不到任何条目

Docker 文件

码头工人撰写:

services:
  core:
    image: core
    build:
      context: .
      dockerfile: ./core/dockerfile
    volumes:
      - C:/site/Default/:c:/inetpub/wwwroot:rw
    ports:
      - "8000:80"
      - "4020-4024:4020-4024"
    environment:
      DatabaseType: SqlServer
      ConnectionString: Server=sqldata;User ID=sa;Password=pAssword123;Database=Default;MultipleActiveResultSets=True
    depends_on:
      - sqldata

  sqldata:
    ...

码头文件:

FROM microsoft/aspnet:4.6.2

# Also tried the bellow command with /l
RUN icacls --% "C:\inetpub\wwwroot" /grant Everyone:(OI)(CI)F /t

【问题讨论】:

  • 一开始就不要在那里写。这是 IIS 中所有网站的根文件夹。应用程序池帐户不允许写入 tehre。应用程序池帐户已有权写入其站点的根文件夹
  • 如果您削弱安全性并允许应用程序池帐户在那里写入,那么入侵该帐户的网站将允许其他人修改其他网站和应用程序。
  • 我正在尝试对现有的遗留应用程序进行 docker 化。我知道这不是推荐的方式,但我需要继续这样做作为第一步。
  • 在这种情况下,您会遇到问题 - 应用程序使用的是硬编码路径,这意味着如果该路径发生更改,它很容易中断,或者它使用了错误的相对路径并且有人决定中断应用程序第一次崩溃时的安全性。尝试将容器的 wwwroot 文件夹映射到 不同的 主机文件夹。 Check this question.
  • 应用程序从 wwwroot 路径构建路径:File.WriteAllText(Path.Combine(WWWRootPath, "agenda.css"), ...) 我尝试按照建议映射到不同的主机文件夹,没有变化...

标签: asp.net windows docker symlink docker-volume


【解决方案1】:

由于某些原因,IUSR 有权写入容器文件夹中的任何位置(是否已映射),C:\inetpub\wwwroot 除外。 IIS 阻止写入此特定路径。

我最终创建了一个应用程序,它使用 dockerfile 中的另一个物理路径,现在一切正常:

FROM microsoft/aspnet:4.6.2

RUN C:\Windows\system32\inetsrv\appcmd.exe set app \"Default Web Site/\" /physicalPath:C:\SomeOtherMountPoint

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2012-10-10
    • 2013-06-05
    • 2016-06-15
    • 1970-01-01
    • 2017-02-05
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多