Re: Creating/editing user accounts
From: Thor@HammerofGod.comDate: 11/08/01
- Previous message: Laura A. Robinson: "Re: Creating/editing user accounts"
- In reply to: Derek T: "Creating/editing user accounts"
- Next in thread: Laura A. Robinson: "Re: Creating/editing user accounts"
- Reply: Laura A. Robinson: "Re: Creating/editing user accounts"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Thor@HammerofGod.com To: sigmafive@hotmail.com Message-Id: <5.1.0.14.0.20011108120805.00adef68@192.168.3.190> Date: Thu, 08 Nov 2001 12:10:30 -0800 Subject: Re: Creating/editing user accounts
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Right off the cuff, I would think it is risky, but do-able. You could
always have the anonymous account run in the context of a specific user
that you have delegated the account operator rights to for a specific
container that you would allow the user's to exist in. Then you would have
a bit of control over it.
AD
At 12:10 PM 11/8/2001 -0500, you wrote:
>A quick question about AD and web enabled services.
>
>The company I work for is trying to offer the ability to open and
>manipulate accounts from the Web ( kind of like Yahoo or Hotmail). The
>problem lies in the choice to use AD on the segmented network. With AD the
>only ID with the rights to create and edit user accounts are sys-admins,
>something that you can not allow anonymous web browsers to assume. Also
>this will be a branch off the main corporate network, ( in it's own DMZ)
>to allow customer service reps to access and work with the same data from
>the main tree. Any ideas on how can this be accomplished and kept secure,
>or is it a pipe dream?
>
>Also in the event that a process is given the Sys-admin rights instead of
>a user, what potential security implications does this pose? It seems as
>if almost every discussion of a new vulnerability starts with " You see,
>there was this process running with administrator rights...." =)
>
>
>Thanks for the insights
>
>D True
>
>
>"If debugging is the process of removing software bugs, then programming
>must be the process of putting them in."- L. Owando
>
>
>
>_________________________________________________________________
>Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp
-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1
iQA/AwUBO+rmtohsmyD15h5gEQLj8ACfeOqbnwIYkbfXA1miZbJAwyuKtuwAoKUg
R441cUtD1A18CGbXZweR8XBf
=KBYT
-----END PGP SIGNATURE-----
- Previous message: Laura A. Robinson: "Re: Creating/editing user accounts"
- In reply to: Derek T: "Creating/editing user accounts"
- Next in thread: Laura A. Robinson: "Re: Creating/editing user accounts"
- Reply: Laura A. Robinson: "Re: Creating/editing user accounts"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|