Re: Looking for feedback on public website security config



Since the web server is a domain controller, there is no way to make local
accounts for IIS to run under. Unless you know of a way.

Thanks for the feedback.

"Anteaus" wrote:

"driley" wrote:

We can isolate this machine and it is one of the steps that I am recommending.

That would be acceptable, though DMZ woudl be better.

Basically, agree with Roger on this one.

Might also add that there are two aspects to 'security' here. SSL and
certificates provide security for the Web user. The do nothing to protect
your other computers from attack should a vulnerability in the webserver be
exploited to gain control of it.

A key piece of protection here is to ensure that the account SIDs and
passwords which the webserver processes run under are different from any
domain useraccounts, or at least any with file-share rights. That way, the
webserver -even if compromised- cannot easily gain access to domain
file-shares.


.



Relevant Pages

  • Re: User Accounts Keep Locking Out
    ... This is a WebServer, not a domain controller by the way. ... someone has some ideas on why these accounts keep locking. ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Domain unavailable for some logons
    ... You probably have a dns problem and the computer that you can not logon to ... with the domain account can not find the domain controller. ... > couple logon accounts for most of the 25 PC's. ...
    (microsoft.public.win2000.security)
  • Re: I hate IIS - "Server Application Unavailable" error message
    ... You can get it running on a domain controller by altering this account. ... Buy a web server. ... configure the <processModel> section of the Machine.config file to use ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Domain Password Security
    ... accounts need to use complex passwords and minimum of ntlmv2 should be used for lan ... Services Client and configuring authentication level on Domain Controller Security ... controllers if you have all W2K/XP computers. ... I also recommend you enable auditing of account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: Domain Password Security
    ... Domain Controller Security ... >controllers if you have all W2K/XP computers. ... >administrator accounts only when needed to, ... account logon and logon ...
    (microsoft.public.win2000.security)