Terminal Services / ActiveX / AD
Terminal Services / ActiveX / AD
Author
Discussion

Big_Dan

Original Poster:

513 posts

282 months

Monday 10th January 2005
quotequote all
Hi all,

We've got a problem with our users on Terminal Services (W2K SP4, latest IE 6 etc etc)

Basically when in IE, any ActiveX control is blocked, great for the Internet, but on our Intranet we heavily use PDFs and SQL Reporting services, both of which use ActiveX controls to work.

I've changed all the setting in AD for IE, security zones, trusted sites, how controls are run and so on, with the security settings on the lowest and manually enabled.

The intranet zone is working fine and I've tried making it a trusted address.

With PDFs, the Adobe control should fire up and display the document, what happens instead is the "Open / Save" dialogue opens and then blocks access to the file.

I'm sure that there must be another setting somewhere in AD I've missed - any ideas? It's a real PITA!

Don

28,378 posts

314 months

Monday 10th January 2005
quotequote all
Spooky. I've literally just had a client call up about how to deal with this!

You've got some options.

1) You can extract your ActiveX controls and register them on the Terminal Server manually ahead of time - then they'll be available for all users.

If you have client machines you need to get the controls to you have two options:

1) Make users "Power Users" and then IE will be allowed to download and fire off ActiveX controls

2) Distribute the ActiveX controls via Active Directory. You can even have IE fire off the Windows Installer service on demand to do this..but your supplier will need to supply you with MSI packages for the controls and you'll have to do some interesting Group Policy shenanigans.

Plotloss

67,280 posts

300 months

Monday 10th January 2005
quotequote all
By far the easiest way is to ship the OCX's onto the Terminal Server and register them there...

Big_Dan

Original Poster:

513 posts

282 months

Monday 10th January 2005
quotequote all
Thanks for the reply

The controls work fine when you're logged on locally, but in this case you aren't restricted by the AD group policies. There's something in there somewhere that's blocking them.

Don

28,378 posts

314 months

Monday 10th January 2005
quotequote all
Big_Dan said:
Thanks for the reply

The controls work fine when you're logged on locally, but in this case you aren't restricted by the AD group policies. There's something in there somewhere that's blocking them.


So the controls are already ON the Terminal Server, registered and working? Its just end-users aren't allowed to use them?

You might want to check file permissions on the OCX files. IE policy may be preventing them from running too. Are the controls all "Signed" and "Marked as Safe For Scripting"? You'll get trouble if they're not. The last two things require the developers of the controls to have done some work - but it is usually done...

Big_Dan

Original Poster:

513 posts

282 months

Monday 10th January 2005
quotequote all
Yep, all works fine as an admin.

Primarily the control is for PDFs, but it includes all of them. It will also block a, for example, word document with the same dangerous download / save dialogue. Right click save as is also blocked, but it is access to the file that is the problem.

Big_Dan

Original Poster:

513 posts

282 months

Wednesday 9th February 2005
quotequote all
Still struggling with this ...

I thought it might be something getting blocked when the temp file is created before it displayes the PDF or whatever on the screen - but it isn't.

It must be something in a group policy somewhere?

Installing Office XP SP3 was a bad idea too - as the same thing is blocking any embedded content in word / excel as well now - even simple things like a logo.

grrr.