Re: SUS question

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 12/16/03


Date: Tue, 16 Dec 2003 12:39:17 -0500

I would imagine it might be for security reasons. Installing IIS onto
servers with other functions is generally to be avoided. SUS is fairly
secure when the IISLockdown and URLScan installer run, but if you have to
uninstall and reinstall IIS for any reason [for example, to fix a problem],
it appears to me that IISLockdown does not run again automatically even if
you re-run the SUS install, and you get some insecure default settings
unless you manually run IISLockdown. [And if you re-run IIS Lockdown
manually, you get some problems that you have to manually figure out how to
fix, such as permitting .EXE file downloads via the URLSCAN.INI file.]

"Dave" <dave@wellesley13.freeserve.co.uk> wrote in message
news:OeVLHX$wDHA.2708@TK2MSFTNGP09.phx.gbl...
> This seems the best NG for my question so here goes.
> MS recommend installing SUS on a dedicated server. Does anyone know why
> this is ? I appreciate the web server is heavily locked down when
> installing SUS and can see why you wouldn't want to run other web sites on
> the same box. But, why would SUS affect other services, say DHCP ?
> I may have to install SUS ona box running DHCP, RAS and WINS. The load is
> very light. Can anyone explain why this is a bad idea ?
>
> Dave
>
>



Relevant Pages

  • Re: Open ports?
    ... Initially, Win2k-Server was installed without IIS and SP2 installed, active ... This server isn't going to be as secure as possible. ... > Microsoft recommends not installing OWA on the same server that is running ... > You may want to consider using two firewalls or a firewall with three NICs ...
    (microsoft.public.win2000.security)
  • Re: Open Ports....How to block them all....?
    ... >> What can be done to secure this server so that this doesn't keep> happening? ... Frequently this happens through an IIS> vulnerability. ... Installing Serv-U software typically involves a> person having the ability to remotely run commands and install files on your> system, ... > Remember that security is not just patches but also proper configuration and> third party hardening tools. ...
    (microsoft.public.inetserver.iis.security)
  • RE: Microsoft .NET, ASP.NET, and IIS - any opinions?
    ... concerns were over the potential accessibility of the compilers and code ... through the server, any new ports that might have to be opened, and things ... > To the best of my knowledge, the SDK doesn't seriously modify IIS except ... > installing Perl, ...
    (Focus-Microsoft)
  • Re: CCM Server Framework Pool dies along with W3SVC in event log
    ... What's odd is that SMS and IIS are working ... installing and configuring the Site Server. ... "Marin Marinov" wrote: ...
    (microsoft.public.sms.admin)
  • Re: Win2k3,IIS6,FPSE2002 Help!
    ... I'm about to uninstall/reinstall IIS and FPSE again. ... Should I select front page 2002 server ... separately after installing IIS? ... > Mukilteo, WA USA ...
    (microsoft.public.frontpage.extensions.windowsnt)