Active Directory and IIS on production servers, and clustering

From: Derick Anderson (danderson_at_vikus.com)
Date: 09/26/05

  • Next message: Derick Anderson: "RE: Active Directory and IIS on production servers, and clustering"
    Date: Mon, 26 Sep 2005 14:01:54 -0400
    To: "Focus-MS" <focus-ms@securityfocus.com>
    
    

    The company I work for (as the only systems administrator) is
    considering a new implementation of their web-based software. To support
    this we will be splitting our single domain into two domains, one for
    production servers and one for employee support (file servers and
    employee workstations). We'll be using at least two IIS servers as a
    front-end to a custom-built service in the production domain.
     
    We are a fairly small company and my CIO does not believe we should
    invest money in two dedicated domain controllers for the production
    domain. He thinks that because Active Directory is not resource
    intensive that it wouldn't be a problem to make the IIS servers domain
    controllers. (The back-end servers, except for SQL Server 2000, would
    not require Windows Server 2003.) I disagree completely, for several
    reasons that I thought were obvious:

    1. Separation of roles is essential to security as well as reliability.
    2. Highly sensitive services such as internal DNS and Active Directory
    should never reside on a publicly accessible server.
    3. In general, web applications are the biggest attack surface of any
    organization in terms of threat volume and relative ease of
    exploitation.

    I'd appreciate any thoughts on this as I am fighting to follow best
    practices in our server environments. I've been reading the Windows
    Server 2003 Security Guide which unfortunately lacks the "Never ever
    have your production IIS servers be domain controllers" statement but
    implies Reasons #1 and #2 with its approach to server hardening.

    My second question has to do with clustering: we plan to eventually
    cluster the IIS servers. What impact does that have on Active Directory
    services?

    Thanks,

    Derick Anderson

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Derick Anderson: "RE: Active Directory and IIS on production servers, and clustering"

    Relevant Pages

    • Re: is vmware used in customer development purpose?
      ... How can they not support such a widely spread VM? ... support VmWare or other hypervizors other than MS. ... the FE servers are VM's and one BE server, ... Its not supported in production however. ...
      (microsoft.public.exchange.applications)
    • Re: is vmware used in customer development purpose?
      ... How can they not support such a widely spread VM? ... VmWare is by far the most common VM plattform and in my eyes much ... all the FE servers are VM's and one BE server, ... Its not supported in production however. ...
      (microsoft.public.exchange.applications)
    • Re: DC fails to authenticate when trusted DCs unavailable?
      ... They do use DNS servers from only their own domain, ... To complicate matters, our DCs are also our DNS servers, and the DNS ... e.g. no corporate DCs in the production site. ...
      (microsoft.public.windows.server.networking)
    • RE: SMP Performance (Was: Re: Are hardware vendors starting to bail ... )
      ... I agree with few posters that FreeBSD performance have been lacking behind. ... Personally, I've never found HT to be a performance boost, and I run 9 'production hosting servers' ... ... on a simple production server, not doing much, I doubt anyone would ever see the file system deadlocks ... ...
      (freebsd-questions)
    • PHB asks question, ignores answer
      ... A PHB (FSVO, I have not yet found out which particular pointy it ... was) decided to close out one of our offices in London. ... contained three production servers for which I am responsible, ...
      (alt.sysadmin.recovery)

  • Quantcast