Search Returns Hits to Users Who Do Not Have Permissions

ID: Q237564


The information in this article applies to:
  • Microsoft Site Server version 3.0


SYMPTOMS

If you create a catalog using a file crawl and map the file ACLs, some files with a large number of access control entries appear in the client search results even if you do not have permission to view them. When you select the file or URL from the result page, Internet Information Server (IIS) displays a Basic Authentication dialog box.


CAUSE

When you search a Site Server Search catalog, if you do not have permission to an object, it will not be displayed in the result page. The symptoms only occur when the number of access control entries exceeds the default buffer size. This can happen after 14 access control entries on an individual file. Site Server Search does not have a large enough buffer to hold all of the ACLs.


WORKAROUND

Assign fewer than 14 access control entries to the file.


RESOLUTION

To resolve this problem, obtain the latest service pack for Site Server 3.0. For additional information, please see the following article in the Microsoft Knowledge Base:

Q219292 How to Obtain the Latest Site Server 3.0 Service Pack


STATUS

This problem was first corrected in Site Server 3.0 Service Pack 3.

Additional query words:

Keywords : SS3SP3Fix
Version : winnt:3.0
Platform : winnt
Issue type : kbbug


Last Reviewed: October 26, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.