CodeVerge.Net Beta


   Explore    Item Entry   Register  Login  
Microsoft News
Asp.Net Forums
IBM Software
Borland Forums
Adobe Forums
Novell Forums

MS SQL 2008 on ASP.NET Hosting



Zone: > NEWSGROUP > Asp.Net Forum > windows_hosting.hosting_open_forum Tags:
Item Type: NewsGroup Date Entered: 10/22/2004 10:02:50 PM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
(NR, 0)
XPoints: N/A Replies: 4 Views: 44 Favorited: 0 Favorite
Can Reply:  No Members Can Edit: No Online: Yes
5 Items, 1 Pages 1 |< << Go >> >|
DmitriG
Asp.Net User
Security Templates for GPOs10/22/2004 10:02:50 PM

0/0

Greetings,

According to ?Solutions for Windows-based Hosting with Hosted Exchange 2003? (Volume 6, Book 2) we create couple GPO and import based on Security Templates (DomainControllerV1.inf, mpsserver01.inf, etc.). Then we link those GPO?s to OU?s using GPMC. After moving computers to corresponding OU and applying GPO we receive Warning events in application log:

Source: SceCli
Event ID: 1202
Type: Warning
Description: Security policies were propagated with warning. 0xd : The data is invalid.

This event exists on ALL computers in reference infrastructure, so I will talk only about domain controller as an example because I think the root reason for this warning is the same for ALL Security Templates.

In winlogon.log file I found this messages:

----Configure Security Policy...
Configure password information.
Configure account force logoff information.
Guest account is disabled.

System Access configuration was completed successfully.
LSA anonymous lookup names setting : existing SD = D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS).
Configure LSA anonymous lookup setting.
Configure log settings.

Audit/Log configuration was completed successfully.

Kerberos Policy configuration was completed successfully.
Configure hkey_local_machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
Warning 3: The system cannot find the path specified.
Error configuring hkey_local_machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
Configure hkey_local_machine\system\currentcontrolset\control\lsa\nolmhash.
Warning 3: The system cannot find the path specified.
Error configuring hkey_local_machine\system\currentcontrolset\control\lsa\nolmhash.
Configure hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
Warning 3: The system cannot find the path specified.
Error configuring hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
Configure hkey_local_machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
Warning 3: The system cannot find the path specified.
Error configuring hkey_local_machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
Configure machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
Configure machine\system\currentcontrolset\control\lsa\nolmhash.
Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.
Configure machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
Configure machine\system\currentcontrolset\services\netlogon\parameters\requiresignorseal.
Configure machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.

Configuration of Registry Values was completed with one or more errors.

To solve this problem I deleted WH-Domain controller GPO, updated DomainControllerV1.inf security template by replacing string ?HKEY_LOCAL_MACHINE? with ?MACHINE?, and recreate WH-Domain controller GPO using updated template. So, it solved the problem with Warning in event log on domain controller (and I think it will solve problem on other computers), but I figured out another problem on domain controller.

Almost all settings for Computer configuration\Windows settings\Local policies\ Security options in WH-Domain controller GPO are ineffective because Default Domain Controllers Policy GPO has higher priority than WH-Domain controller GPO (because of the procedure how to create and link policy to OU). For example Domain Controller: LDAP server signing requirements:

Default Domain Controllers Policy: None
WH-Domain controller: Require signing
Effective setting: None

Here are a couple of questions:
1. Should I worry about those GPO?s or I should live it as is?
2. How those policies affects hosting environment?
3. If this issue is critical then how to fix it?

Regards,

Dmitri Gaikovoi

Regards,

Dmitri Gaikovoi

P.S. Checks, mark post as answered, or simple "Thank you" will be really appreciated. Geeked


http://services.mail2web.com
http://myhosting.com
jjstreic
Asp.Net User
Re: Security Templates for GPOs10/26/2004 7:33:18 PM

0/0

I don't believe the templates are required for running Hosted Exchange. That being said they do have some appropriate security settings that you should evaluate deploying with your infrastructure.

I'm checking on the template reg key issue. It has been a long time since I have worked directly with templates so I am setting up a lab. I'll get back to you on that.

I have sent the product team your comments on the Domain Controller policy issue. I checked the documentation and I don't see any mention of prioritizing the policies either. I have sent this question back to the product team for comment.

Thanks!

Technical Account Manager
Microsoft Communication Sector North America
This posting is provided "AS IS" with no warranties, and confers no rights. Script samples are subject to the terms at http://www.microsoft.com/info/cpyright.htm"
mkostersitz
Asp.Net User
Re: Security Templates for GPOs10/27/2004 7:12:23 AM

0/0

THanks for point this out.

The Templates are not required to run Hosted Exchange they are samples and mea culpa faulty ones.

I will fix the templates sometime soon and we will release an update.

HTH
Mike Kostersitz
Senior Program Manager, Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights. Script samples are subject to the terms at http://www.microsoft.com/info/cpyright.htm"
DmitriG
Asp.Net User
Re: Security Templates for GPOs10/27/2004 1:47:12 PM

0/0

Thank you, guys.

Does it mean that I can safely delete all this GPOs?


Regards,

Dmitri Gaikovoi

P.S. Checks, mark post as answered, or simple "Thank you" will be really appreciated. Geeked


http://services.mail2web.com
http://myhosting.com
mkostersitz
Asp.Net User
Re: Security Templates for GPOs10/29/2004 5:21:47 AM

0/0

No you should disable them first so that the Servers pick up the reversion of the settings if you just delete them the 'old' settings are left behind.

Mike
Mike Kostersitz
Senior Program Manager, Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights. Script samples are subject to the terms at http://www.microsoft.com/info/cpyright.htm"
5 Items, 1 Pages 1 |< << Go >> >|


Free Download:

Books:
Hardening Windows Systems: [bulletproof Your Systems Before You are Hacked!] Authors: Roberta Bragg, Pages: 544, Published: 2004
Active Directory Cookbook Authors: Laura E. Hunter, Robbie Allen, Pages: 1072, Published: 2008
McSe Planning and Maintaining a Microsoft Windows Server 2003 Network Infrastructure: Planning and Maintaining a Microsoft Windows Server 2003 Network Infrastructure Authors: Will Schmied, Robert Shimonski, Ed Tittel, Pages: 714, Published: 2004
MCSA/MCSE: Windows Server 2003 Network Security Administration (70-299) Authors: Russ Kaufmann, Bill English, Pages: 608, Published: 2004
The Ultimate Windows Server 2003 System Administrator's Guide Authors: Mark Walla, Pages: 956, Published: 2003
Microsoft Windows Server 2008: The Complete Reference Authors: Danielle Ruest, Nelson Ruest, Pages: 826, Published: 2008
Security Administrator Street Smarts: A Real World Guide to CompTIA Security+ Skills Authors: James M. Stewart, David R. Miller, Michael Gregg, Pages: 456, Published: 2007
Network Security: The Complete Reference Authors: Roberta Bragg, Mark Rhodes-Ousley, Keith Strassberg, Pages: 854, Published: 2004
Securing Windows Server 2003 Authors: Mike Danseglio, Pages: 426, Published: 2004
MCSA/MCSE Managing and Maintaining a Windows Server 2003 Environment for an MCSA Certified on Windows 2000 (Exam 70-292): Managing and Maintaining a Windows Server 2003 Enviroment for an McSa Certified on Windows 2000 Authors: Will Schmied, Robert Shimonski, Syngress, Syngress Media, Inc. Staff, ebrary, Inc, Pages: 800, Published: 2003

Web:
Baselining with Security Templates Sep 30, 2004 ... Using GPOs to implement your security templates are more ... To get the security templates into the GPOs, you will need to edit the GPOs ...
Understanding Windows Security Templates Oct 6, 2004 ... Security templates can be deployed centrally using Group Policy objects (GPOs). Finally, security templates can be customized to include ...
Importing Security Templates and Modifying Security Settings in a ... Importing Security Templates and Modifying Security Settings in a GPO. Updated: March 28, 2003. By using Group Policy Object Editor and a security template, ...
Customizing Local Security Policies | O'Reilly Media Mar 15, 2005 ... Customizing the Security Options policies of Group Policy is a great way to ... Import a default security template into an existing GPO to ...
Security Templates for GPOs - ASP.NET Forums According to “Solutions for Windows-based Hosting with Hosted Exchange 2003” ( Volume 6, Book 2) we create couple GPO and import based on Security Templates ...
How to apply more restrictive security settings on a Windows ... Then, you must apply more restrictive security settings by using the security template. Alternatively, configure an OU GPO, and then import the template ...
Enterprise Systems | Using Windows Security Templates for Baselines Instead, you can use GPOs to deploy the security templates. ... To get the security template into the GPO, edit the GPO using either the Active Directory ...
- Applying Security Template Through GPOs TechExams.net MCSA, MCSE, MCTS, A+, Network+, Security+, CWNA, CISSP, CCNA, CCNP and CCIE certification forums.
GPO and Security Template conflict Report as spam Question - Post 1 of 2; GPO and Security Template conflict: My girlfriend works for the city, (can't tell you which one). ...
ITT: Using Security Templates and the SCW in Windows Server 2003 Aug 12, 2005 ... You will need them BOTH to create a secure enviroment... use GPO's as the end- result. Inport Security Templates into CWS files during ...

Videos:
Web Applications and the Ubiquitous Web Google TechTalks February 1, 2006 Dave Raggett Dave Raggett is currently a W3C Fellow from Canon, and W3C Activity Lead for Multimodal ...




Search This Site:










pathtoolongexception with some modules

problem with install of dnn 4.0

case sensitive sql server install failure

intall working but problem with the rich text editor

bulding my own security checklist - any suggestions?

upgrading error from dnn3.0.1 to 3.1.1

i'm sorry i just have to say this...

portal transfer

disappearing images in html/text module?

dnn menu style in 3.2.1 not working was fine in 3.1.1

questions about the ability to unregister

using editurl() on a page

error to install

newbie - can't login

dotnetnuke site url

dotnetnuke and asp.net 2.0

error when trying to install dnn module

changing documents module

creating dnn modules with asp.net 2.0 / vs2005?

url automatically back to localhost

dnnxxl1.0.10 setup problem

anyone ever get this error while installing a module?

how do i use an ip:port address in an iframe??

visual studio.net 2003 errors

error loading module, please help!

host provider is supposed to install 'member role scripts' ??

installation problem

install problem - is it asp.net ?

quick import/export question

new to dnn

  Privacy | Contact Us
All Times Are GMT