RE: Exchange mail server settings - easy dump possible?

From: Beauford, Jason (jbeauford_at_EightInOnePet.com)
Date: 05/24/05

  • Next message: Roman Medina-Heigl Hernandez: "Re: looking for a HTTPS redirect tool"
    Date: Tue, 24 May 2005 14:38:07 -0400
    To: "Sullivan Tim P" <tim@nativemode.com>, <Petr.Kazil@eap.nl>, <pen-test@securityfocus.com>
    
    

    Within ADSIEdit, I found some interesting Exchange settings. Not sure
    if anything there can help you.

    JMB

    -----Original Message-----
    From: Sullivan Tim P [mailto:tim@nativemode.com]
    Sent: Tuesday, May 24, 2005 2:01 AM
    To: Petr.Kazil@eap.nl; pen-test@securityfocus.com
    Subject: RE: Exchange mail server settings - easy dump possible?

    Not that I know of.

    Since securing exchange relies on file permissions, services, registry
    settings, and proper server configuration, I would think it would be
    hard to just dump all of the settings to a file for reimporting later.
    Especially when AD and the server name are all intertwined as well.

    Normally policies in exchange would be setup to allow you to standardize
    some settings across your exchange environment, and GPO's would be used
    to further standardize.

    But its not really meant to go from lab to production.

    Tim

    -----Original Message-----
    From: Petr.Kazil@eap.nl [mailto:Petr.Kazil@eap.nl]
    Sent: Monday, May 23, 2005 9:58 AM
    To: pen-test@securityfocus.com
    Subject: Exchange mail server settings - easy dump possible?

    I've been playing with a trial version of Exchange Server 2003. Using
    the NIST, NSA and Microsoft security guidelines I'm getting a better
    idea of the relevant security settings. But it's a pain to click through
    all the relevant screens in the System Manager GUI.

    Is there a tool that dumps all the settings in one readable text file -
    for example like Dumpsec ? I haven't been able to find it yet.

    I have found and used the Exchange Best Practices Analyzer Tool, and it
    works fine and covers some of the relevant settings but (AFAIK) not all
    of them.

    Or are the settings stored in the registry, a config file or an XML-file
    with settings somewhere? I'm reluctant to try scripting, because I fear
    that the learning curve will be steep (I know VBscript but not the
    WMI/API interfaces I would probably need).

    I will search through my old WindowsITPro magazines and probably it will
    be in here somewhere ...

    Thanks for any suggestions.
    Petr


  • Next message: Roman Medina-Heigl Hernandez: "Re: looking for a HTTPS redirect tool"

    Relevant Pages

    • Re: Exchange 2003 SP2 - able to send but not receive email
      ... product and not part of Exchange Server itself. ... OWA already setup and running - My whole goal is to setup this server to ... settings it successfully saved my settings - ...
      (microsoft.public.exchange.admin)
    • Re: Can not email to the same domain?
      ... some time for these settings to propagate and for routing to recalculate. ... Confirm that your problem is sending mail outside Exchange for a domain ... both of these have authoritative responsibility. ... virtual server properties are: ...
      (microsoft.public.exchange.admin)
    • SMTP Issues
      ... I have had numerous problems with trying to send e-mail since installing SBS ... 2003 with Exchange. ... I have SBS 2003 also set up as the DHCP server. ... settings as well as the "Small Business SMTP Connector" settings. ...
      (microsoft.public.exchange.setup)
    • Re: BF/FE and RPC/HTTP
      ... Client should be configured in the Outlook profile for "Exchange Server ... connection from the client, you will need to click on "More Settings", then ...
      (microsoft.public.exchange.admin)
    • Re: How do I receive an access database?
      ... I have only used recent versions of Outlook in conjunction with Exchange ... Server, and should have been clear on that point. ... There is no control over those files (no settings within ...
      (microsoft.public.access.gettingstarted)