Re: general security settings



On Feb 29, 9:00 am, "Dr. Mark Rhodes" <M...@xxxxxxxxxxxxxxxx> wrote:
I am very new to IIS and the security issues of having our own web server.
We have Windows 2003 Server with the latest updates and IIS 6.

I just found the Resource Kit Tools and assume it might be helpful.

Should I be concerned about changing some of the settings in IIS right from
the beginning? Or should I leave the default settings as is?

Thanks.

Mark



For most users, IIS6 default settings are sufficiently secure.

Can you first define your requirements for security, how you want to
evaluate the software system (in this case IIS6) against your
requirements, and whether there are any failed requirements which
require IIS6 configuration change?


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
.



Relevant Pages

  • Re: HTTP Error 403.6 - Forbidden: IP Address Rejected
    ... it was the proxy settings on the ... > You can also try to change the security settings for the Remote Web ... Open the IIS console ...
    (microsoft.public.windows.server.sbs)
  • Re: ASP.NET webs not working
    ... application settings were simple and easily reversible in an effort to ... The Default Web Site in IIS has "Anonymous access" checked. ... The default security and applications should be correctly configured by ...
    (microsoft.public.frontpage.client)
  • Re: IIS6.0 not allowing file creation on Windows Server2003
    ... Run FileMon and IIS6 in native mode, ... The IIS identity depends on the authentication type you configured in IIS ... The process identity depends on the IIS process model. ...
    (microsoft.public.inetserver.iis)
  • Re: IIS security settings are reset after I reboot the server
    ... Stopping and restarting the IIS services should let you see if the ... security settings are going to disappear or not after a reboot [in other ... I believe the IIS settings may be disappearing when the services are ... Then, restart W3SVC service. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Customerrors in web.config question
    ... description on the different levels of error handling in IIS 6 and ASP.NET ... > error settings defined within the IIS metabase and not by the ... >>web.config file with a customerrors element that points the error handling ...
    (microsoft.public.dotnet.framework.aspnet)