The Remote Access Service Security DLL Is Incorrectly Used to Authenticate Non-Modem Remote Access Connections (815182)



The information in this article applies to:

  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server

SYMPTOMS

When you create and install a custom Remote Access service security DLL on a Windows 2000 Server-based computer that is running the Routing and Remote Access service to authenticate remote users, the RAS security DLL may be incorrectly used to authenticate remote users who use a connection type other than a modem connection. For example, the Remote Access service security DLL is used to authenticate users who connect by using a Virtual Private Networking (VPN) connection. Because of this, VPN users may receive an "Error 619" error message when they try to access the server.

CAUSE

This problem occurs because Windows does not check the connection type before it calls the Remote Access service security DLL. Because of this, the Remote Access service security DLL is used for both modem and non-modem connections.

RESOLUTION

Service Pack Information

To resolve this problem, obtain the latest service pack for Microsoft Windows 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:

260910 How to Obtain the Latest Windows 2000 Service Pack

Hotfix Information

A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that are experiencing this specific problem. This fix may receive additional testing. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Windows 2000 service pack that contains this hotfix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The typical support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

The global version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
   Date         Time   Version        Size    File name
   -----------------------------------------------------
   20-Feb-2003  20:15  5.0.2195.6666  69,904  Mprddm.dll
Note Because of file dependencies, this update requires Windows 2000 Service Pack 3 (SP3).


STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Microsoft Windows 2000 Service Pack 4.

MORE INFORMATION

As of March 2003, Windows 2000 provides Remote Access service security host support for asynchronous modem connections only. The following other types of connections are not supported:
  • Ethernet, which is not a modem connection.
  • VPN, which is not a modem connection.
  • ISDN, which is a synchronous connection.
For more information about Remote Access service security host support and the Remote Access service security DLL, view the Remote Access service Security Host Support topic in the Remote Access Service section of the Microsoft Platform SDK documentation. To view this documentation, visit the following Microsoft Web site:

Modification Type:MinorLast Reviewed:10/10/2005
Keywords:kbHotfixServer kbQFE kbWin2kSP4fix kbnetwork kberrmsg kbenv kbprb kbQFE kbWin2000preSP4Fix kbfix kbbug KB815182