# Installing a package from a password-protected UNC share

**URL:** <https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562>\
**Category:** Chef Infra (archive)\
**Created:** [January 31, 2013, 12:58pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562 "2013-01-31T12:58:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrea\_Campi](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/andrea_campi/32/514_2.png) [@Andrea\_Campi](https://discourse.chef.io/u/Andrea_Campi)\
**Post date:** [January 31, 2013, 12:58pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/1 "2013-01-31T12:58:51Z")

</div>

Ohai Chefs,

I’m seeking help from those of you who have more Windows-fu than I.

I need to install some software from a Windows share.  
Unfortunately there doesn’t seem to be a way to specify username and  
password in a UNC path and give that to either the windows\_service or  
remote\_file resource. Or is there?

Failing that, we tried something like this:

execute “mount share #{drive}” do  
command "net use #{drive}: #{path} /user:#{username} #{password}  
/persistent:No"  
end

windows\_package “Symantec Anti-Virus” do  
source  
"#{drive}:\#{node[‘symantec-antivirus’][‘installer’][‘arch\_file’]}"  
options “/qn ALLUSERS=1 REBOOT=ReallySuppress”

action :install  
end

execute “unmount share #{drive}” do  
command "net use /d #{drive}:"  
end

This sucks in many ways (deciding which drive letter to use is tricky, any  
failure will leave mapped drives around, …).

Worse, it doesn’t work when chef-client is run a service!

STDERR: System error 1312 has occurred.

A specified logon session does not exist. It may already have been  
terminated.

Googling about this stuff, it seems there is a way around this error by  
using a PSEXEC.EXE, but I would rather avoid that is possible.

Thoughts?

Andrea

---

<div class="post-metadata">

**Author:** ![Jesse\_Campbell](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jesse_campbell/32/251_2.png) [@Jesse\_Campbell](https://discourse.chef.io/u/Jesse_Campbell)\
**Post date:** [January 31, 2013, 4:07pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/2 "2013-01-31T16:07:10Z")

</div>

what about using what you have there, but skipping the drive letter?  
If i remember correctly you can leave that out, and it will assign it to a  
void mount, then you can access it using the original UNC path...  
so to get a directory listing it would look like:  
net use //myserver/myshare /user:me pass  
dir //myserver/myshare/myfolder  
net use //myserver/myshare /delete

or maybe you have to use \ instead of //... again, been a few years 😉  
-Jesse

On Thu, Jan 31, 2013 at 7:58 AM, Andrea Campi  
[andrea.campi@zephirworks.com](mailto:andrea.campi@zephirworks.com)wrote:

> Ohai Chefs,
> 
> I'm seeking help from those of you who have more Windows-fu than I.
> 
> I need to install some software from a Windows share.  
> Unfortunately there doesn't seem to be a way to specify username and  
> password in a UNC path and give that to either the windows\_service or  
> remote\_file resource. Or is there?
> 
> Failing that, we tried something like this:
> 
> execute "mount share #{drive}" do  
> command "net use #{drive}: #{path} /user:#{username} #{password}  
> /persistent:No"  
> end
> 
> windows\_package "Symantec Anti-Virus" do  
> source  
> "#{drive}:\#{node['symantec-antivirus']['installer']['arch\_file']}"  
> options "/qn ALLUSERS=1 REBOOT=ReallySuppress"
> 
> action :install  
> end
> 
> execute "unmount share #{drive}" do  
> command "net use /d #{drive}:"  
> end
> 
> This sucks in many ways (deciding which drive letter to use is tricky, any  
> failure will leave mapped drives around, …).
> 
> Worse, it doesn't work when chef-client is run a service!
> 
> STDERR: System error 1312 has occurred.
> 
> A specified logon session does not exist. It may already have been  
> terminated.
> 
> Googling about this stuff, it seems there is a way around this error by  
> using a PSEXEC.EXE, but I would rather avoid that is possible.
> 
> Thoughts?
> 
> Andrea

---

<div class="post-metadata">

**Author:** ![Andrea\_Campi](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/andrea_campi/32/514_2.png) [@Andrea\_Campi](https://discourse.chef.io/u/Andrea_Campi)\
**Post date:** [January 31, 2013, 4:12pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/3 "2013-01-31T16:12:21Z")

</div>

Right, that’s the easy part. The problem is that a logon session seems to  
be required, so this wouldn’t work when running as a service.

---

<div class="post-metadata">

**Author:** ![Jesse\_Campbell](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jesse_campbell/32/251_2.png) [@Jesse\_Campbell](https://discourse.chef.io/u/Jesse_Campbell)\
**Post date:** [January 31, 2013, 4:23pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/4 "2013-01-31T16:23:35Z")

</div>

what about turning off the security policy described in this article?

> **[Archived MSDN and TechNet Blogs](https://learn.microsoft.com/en-us/archive/blogs/)**

the net use command is creating a stored credential, which would normally  
only work when applied to a logon session.

On Thu, Jan 31, 2013 at 11:12 AM, Andrea Campi \<[andrea.campi@zephirworks.com](mailto:andrea.campi@zephirworks.com)

> wrote:

> Right, that's the easy part. The problem is that a logon session seems to  
> be required, so this wouldn't work when running as a service.

---

<div class="post-metadata">

**Author:** ![Jesse\_Campbell](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jesse_campbell/32/251_2.png) [@Jesse\_Campbell](https://discourse.chef.io/u/Jesse_Campbell)\
**Post date:** [January 31, 2013, 4:27pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/5 "2013-01-31T16:27:13Z")

</div>

another option would be to run the service as a real user instead of one of  
the service accounts, though i don't remember the steps to make that happen  
🙂

On Thu, Jan 31, 2013 at 11:23 AM, Jesse Campbell [hikeit@gmail.com](mailto:hikeit@gmail.com) wrote:

> what about turning off the security policy described in this article?
> 
> [Archived MSDN and TechNet Blogs | Microsoft Learn](http://blogs.technet.com/b/askperf/archive/2012/04/18/task-scheduler-error-a-specified-logon-session-does-not-exist.aspx)
> 
> the net use command is creating a stored credential, which would normally  
> only work when applied to a logon session.
> 
> On Thu, Jan 31, 2013 at 11:12 AM, Andrea Campi \<  
> [andrea.campi@zephirworks.com](mailto:andrea.campi@zephirworks.com)\> wrote:
> 
> > Right, that's the easy part. The problem is that a logon session seems to  
> > be required, so this wouldn't work when running as a service.

---

<div class="post-metadata">

**Author:** ![Andrea\_Campi](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/andrea_campi/32/514_2.png) [@Andrea\_Campi](https://discourse.chef.io/u/Andrea_Campi)\
**Post date:** [January 31, 2013, 4:40pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/6 "2013-01-31T16:40:37Z")

</div>

On Thu, Jan 31, 2013 at 5:23 PM, Jesse Campbell [hikeit@gmail.com](mailto:hikeit@gmail.com) wrote:

> what about turning off the security policy described in this article?
> 
> [Archived MSDN and TechNet Blogs | Microsoft Learn](http://blogs.technet.com/b/askperf/archive/2012/04/18/task-scheduler-error-a-specified-logon-session-does-not-exist.aspx)
> 
> the net use command is creating a stored credential, which would normally  
> only work when applied to a logon session.

That's an excellent idea! Our googling hadn't turned that one up 🙂

> another option would be to run the service as a real user instead of one  
> of the service accounts, though i don't remember the steps to make that  
> happen 🙂

Yeah, that's one of options we were considering…

It still feels pretty odd that we need to do this manually; surely somebody  
else has had this problem?  
I.e. chef-client::service should probably take care of this.

---

<div class="post-metadata">

**Author:** ![Tensibai](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/tensibai/32/29_2.png) [@Tensibai](https://discourse.chef.io/u/Tensibai)\
**Post date:** [February 1, 2013, 12:36pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/7 "2013-02-01T12:36:50Z")

</div>

You may also use Network\_service account which is able to establish  
cifs shares from a service.

Le 2013-01-31 17:40, Andrea Campi a écrit  
:

> On Thu, Jan 31, 2013 at 5:23 PM, Jesse Campbell [hikeit@gmail.com](mailto:hikeit@gmail.com)  
> wrote:
> 
> > what about turning off the security policy described in  
> > this article?

> **[Archived MSDN and TechNet Blogs](https://learn.microsoft.com/en-us/archive/blogs/)**

[1]

> > the net use command is creating a stored credential, which  
> > would normally only work when applied to a logon session.
> 
> That's an  
> excellent idea! Our googling hadn't turned that one up 🙂
> 
> > another  
> > option would be to run the service as a real user instead of one of the  
> > service accounts, though i don't remember the steps to make that happen  
> > 🙂
> 
> Yeah, that's one of options we were considering…
> 
> It still  
> feels pretty odd that we need to do this manually; surely somebody else  
> has had this problem?  
> I.e. chef-client::service should probably take  
> care of this.

## Links:

[1]

> **[Archived MSDN and TechNet Blogs](https://learn.microsoft.com/en-us/archive/blogs/)**

---

<div class="post-metadata">

**Author:** ![kkeane](https://avatars.discourse-cdn.com/v4/letter/k/9fc29f/32.png) [@kkeane](https://discourse.chef.io/u/kkeane)\
**Post date:** [February 3, 2013, 4:56am UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/8 "2013-02-03T04:56:32Z")

</div>

Are you working in a domain environment? If not, can you set one up (a Samba-based NT domain should be just fine. Active Directory is better of course)?

With a domain, the computer itself will have a domain account, and you can add computers to the permissions for a share the same way you can give users permissions. I’d recommend creating a group that contains all your computers, and then giving that group permissions on your share.

-----Original message-----  
From:Andrea Campi [andrea.campi@zephirworks.com](mailto:andrea.campi@zephirworks.com)  
Sent:Thu 01-31-2013 05:00 am  
Subject:[chef] Installing a package from a password-protected UNC share  
[To:chef@lists.opscode.com](mailto:To:chef@lists.opscode.com);

Ohai Chefs,  
I’m seeking help from those of you who have more Windows-fu than I.  
I need to install some software from a Windows share.  
Unfortunately there doesn’t seem to be a way to specify username and password in a UNC path and give that to either the windows\_service or remote\_file resource. Or is there?  
Failing that, we tried something like this:  
execute “mount share #{drive}” do  
command “net use #{drive}: #{path} /user:#{username} #{password} /persistent:No”

end

windows\_package “Symantec Anti-Virus” do  
source "#{drive}:\#{node[‘symantec-antivirus’][‘installer’][‘arch\_file’]}"  
options “/qn ALLUSERS=1 REBOOT=ReallySuppress”

action :install  
end

execute “unmount share #{drive}” do  
command "net use /d #{drive}:"  
end

This sucks in many ways (deciding which drive letter to use is tricky, any failure will leave mapped drives around, …).  
Worse, it doesn’t work when chef-client is run a service!

STDERR: System error 1312 has occurred.

A specified logon session does not exist. It may already have been terminated.

Googling about this stuff, it seems there is a way around this error by using a PSEXEC.EXE, but I would rather avoid that is possible.  
Thoughts?

Andrea

---

<div class="post-metadata">

**Author:** ![Andrea\_Campi](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/andrea_campi/32/514_2.png) [@Andrea\_Campi](https://discourse.chef.io/u/Andrea_Campi)\
**Post date:** [February 3, 2013, 3:59pm UTC](https://discourse.chef.io/t/installing-a-package-from-a-password-protected-unc-share/3562/9 "2013-02-03T15:59:22Z")

</div>

On Sun, Feb 3, 2013 at 5:56 AM, Kevin Keane Subscription \<  
[subscription@kkeane.com](mailto:subscription@kkeane.com)\> wrote:

> \*\*
> 
> Are you working in a domain environment? If not, can you set one up (a  
> Samba-based NT domain should be just fine. Active Directory is better of  
> course)?

Unfortunately not, neither is an option. Too bad, because what you suggest  
would be a nice and proper fix.
