RE: Share Point?

From: Harbar, Spencer (spencer.harbar_at_dns.co.uk)
Date: 05/13/03

  • Next message: :: gary ::: "Harden ASP.NET Configuration"
    Date: Tue, 13 May 2003 10:07:31 +0100
    To: "Derek Schaible" <dschaible@cssiinc.com>, <focus-ms@securityfocus.com>
    

    I'd look at using ISA Feature Pack 1 to Web publish the Sharepoint
    server rather than placing it on the DMZ.
    This prevents all the "SharePoint in Extranet" scenario configuration
    which is often troublesome.

    Checkpout the ISA FP1 scenarios for more information, and also
    www.spsfaq.com for general SPS info.

    hth
    Spence

    -----Original Message-----
    From: Derek Schaible [mailto:dschaible@cssiinc.com]
    Sent: 09 May 2003 14:33
    To: focus-ms@securityfocus.com

    Greetings List,

    I have a customer who wants to place sharepoint in a DMZ for outside
    clients to access documents. It is their intent to place all of their
    data regarding a project on the SharePoint server and use that as the
    single point of storage for this project. Meaning, everyone on the team
    uses this one share in the DMZ.

    Does this sound safe? Has anyone here tested Share Point's security?
    I'm sure this isn't the first time someone has needed to do something
    like this, how have some of you handled this scenario?

    I appreciate anyone's input on this matter and any advice at all is
    welcome!

    Thanks,
    Derek

    ------------------------------------------------------------------------
    -----
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s
    most recognized corporate security certification track, provides a
    comprehensive prospectus based upon the core principle concepts of
    security. This ALL INCLUSIVE curriculum utilizes lectures, case studies
    and true hands-on utilization of pertinent security tools. For a limited
    time you can enter for a chance to win one of the latest technological
    innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------
    ------

    **********************************************************************
    This email and any files transmitted with it are confidential and
    intended solely for the use of the individual or entity to whom they
    are addressed. If you have received this email in error please notify
    the sender immediately and then delete from your system.

    This footnote also confirms that this email message has been swept
    for the presence of known computer viruses.

    **********************************************************************

    -----------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------------


  • Next message: :: gary ::: "Harden ASP.NET Configuration"

    Relevant Pages

    • RE: Share Point?
      ... Sharepoint actually has the ability to use either Domain logins or locally ... Has anyone here tested Share Point's security? ... >INCLUSIVE curriculum utilizes lectures, ... For a limited time you can enter for a chance ...
      (Focus-Microsoft)
    • Share Point?
      ... I have a customer who wants to place sharepoint in a DMZ for outside clients ... Has anyone here tested Share Point's security? ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
      (Focus-Microsoft)
    • RE: Share Point?
      ... Be sure to make a note that Sharepoint (at least sharepoint team ... Normally the local users are pretty stripped down, ... Has anyone here tested Share Point's security? ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
      (Focus-Microsoft)
    • RE: Share Point?
      ... Couldn't you make that server its own PDC/Domain within the DMZ in order to ... Has anyone here tested Share Point's security? ... INCLUSIVE curriculum utilizes lectures, ... For a limited time you can enter for a chance ...
      (Focus-Microsoft)
    • RE: Share Point?
      ... make it on a domain controller. ... I'm not sure about sharepoint server, ... Has anyone here tested Share Point's security? ... INCLUSIVE curriculum utilizes lectures, ...
      (Focus-Microsoft)