Re: Creating/editing user accounts
From: Laura A. Robinson (larobins@bellatlantic.net)Date: 11/08/01
- Previous message: Robert: "RE: Tunnelling SMB over SSH or SSL"
- In reply to: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Next in thread: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Reply: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <01a601c168a6$8af29ca0$01000001@lauradominion.com> From: "Laura A. Robinson" <larobins@bellatlantic.net> To: <Thor@HammerofGod.com> Subject: Re: Creating/editing user accounts Date: Thu, 8 Nov 2001 17:41:42 -0500
inline responses and snippage...
> AFAIAC, allowing any un-trusted process to create objects in AD, even in
> its own forest, is too much of a security risk. I would have the model
> based on some type of db records before I actually had them live in
> AD.
As would I. By doing this, you could gain more fine-grained control of
things such as requiring fields that would not necessarily be required by
default without having to modify the schema; applying data validation rules;
allowing a process to create the user object so that it would not be
necessary to delegate permissions to do so directly to the web users; and
even creating processes to approve the creation of the user objects before
they were added to AD.
> Heck, even the default Authenticated User's policy allowance of
> creating up to 10 machine accounts in AD is too much for me!
Ah, but that is easily fixed, which was the rationale behind it, IIRC. It is
simpler to remove that capability than it is to grant it, and setting it as
a default allows users to add their machines in the event that they're
running a scripted install, etc. In an internal environment, it is often a
useful setting, but in a DMZ forest, I'd be removing that right immediately.
The last thing I would want is some malicious d00d adding his machines to my
domain, DMZ or not. :-)
>
> I can see some posting script flooding AD with a million entries to crash
> it... infrastructure masters going nuts replicating global catalogs and
all
> kinds of fun stuff ;)
In theory, they could try to do this even with a separate database serving
as the initial entry point for the data, but it would certainly be more
controllable.
>
> But hey, he asked! You know there really are a lot of things he could
> do... Hmm, I wonder if Marc will allow us to go off on a "What If" tangent
> with AD possibilities??
Probably not. ;-)
Laura
- Previous message: Robert: "RE: Tunnelling SMB over SSH or SSL"
- In reply to: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Next in thread: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Reply: Thor@HammerofGod.com: "Re: Creating/editing user accounts"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|