Domain controller setup help

From: Scott Ehrlich (se_at_panix.com)
Date: 07/03/03

  • Next message: panda: "event viewer and log-ons"
    Date: 2 Jul 2003 20:01:36 -0400
    
    

    Authentication question:

    As I prepare to set up a Windows Server 2003 domain controller, it is
    likely we will have separate ldap and kerberos servers. Can the domain
    controller support this? If so, how?

    Also, would this type of setup permit transparent authentication from a
    Windows box to a network storage device on the UNIX side? At present, we
    need to enable unencrypted passwords to third-party SMB hosts, then the
    user needs to log into their Windows box, and then again when mapping to
    the network storage. A single logon is the goal.

    Security question:

    For Win NT-based machines, particularly Win2K and XP, I disable SSDP,
    ICF/ICS, Remote Registry, and any web services.

    For the 2003 server, what security settings should I be aware of, both
    from a services viewpoint as well as permissions (both console and
    remote/network) from/for user accounts and any other area I should be
    aware of.

    There may be documentation on it, but what have people done in practice?
    If they are the same, that is fine, but I do want to make sure this gets
    done right the first time as much as possible.

    Thanks so much in advance.

    Scott


  • Next message: panda: "event viewer and log-ons"

    Relevant Pages

    • Site-tosite VPN Issue
      ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
      (microsoft.public.windows.server.networking)
    • RE: Internet Connection Wizard failing at Firewall Config and Secu
      ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
      (microsoft.public.windows.server.sbs)
    • RE: Provide feedback to DC promotion/replacement
      ... one of the is reffering to a Windows 2000 ... As i sad in the previous posts, to rename a domain controller ... controllers in the domain must be running Windows Server 2003. ... a global catalog. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Windows 2003 DCPROMO Problem
      ... Controllers and you want to add a Windows Server 2003 Domain Controller. ... "Nejmos Saqeb" wrote in message ...
      (microsoft.public.windows.server.active_directory)
    • RE: Transfer roles
      ... own exchange server, would it be possible to setup the two new servers with ... fresh copies of windows 03 and exchange on one of them. ... > on the new servers I am only given the option to install Win 03 and Win ... > Run dcpromo and make it a domain controller for the existing domain. ...
      (microsoft.public.windows.server.migration)