Re: How ti configure a web server ?

From: Robert Moir (bofh@mvps.org)
Date: 02/22/03


From: "Robert Moir" <bofh@mvps.org>
Date: Sat, 22 Feb 2003 11:17:56 -0000


GN wrote:
> Hi,
>
> I need to configuer a standalone web server (with a public URL and
> without any connection on a local net work). Should i configure a
> domain controller, a domain member or just a workgroup.
>
> If i have a choice, what is the best in term of security ?

If your machine is isolated from your LAN (which is what I think you are
saying above) then its not possible to configure it to be a domain member -
it can't contact a domain so it can't be a member of one.

If your machine is standing by itself it really doesn't matter what you set
it to be out of the remaining choices from a security point of view. Domain
controller is a bad choice for a secure internet machine generally, because
if an intruder breaks into a domain controller they have in effect broken
into the whole domain, and maybe your whole forest. But if the machine is
isolated from your network this normal restriction does not apply.

Being a standalone (workgroup) machine carries less performance overhead
than running domain controller tasks so logically setting the machine up in
it's own workgroup would be your best choice.

If you were using this machine on a LAN, your choices in order of preference
from a security point of view would be: Standalone workgroup machine, domain
member, and domain controller would be a very bad 3rd choice which you
should only use if you absolutely have no choice.

--
--
Robert Moir, Microsoft Windows MVP
To search the MS Knowledge base use the link below:
http://support.microsoft.com/support/search/c.asp?PSL=1
My Homepage - http://www.robertmoir.co.uk
** Emailed questions will not be answered **


Relevant Pages

  • Re: force xp domain member to drop from domain?
    ... When I click the "workgroup" radio and type in a workgroup name (any ... controller, Windows XP SP3 client). ... then shutdown both the domain controller and the XP client. ... a computer from being a domain member to being a workgroup member. ...
    (microsoft.public.windows.server.active_directory)
  • Simple install problem
    ... It installed as standalone in WORKGROUP. ... I need is domain controller. ... It didn't ask me if I want to install it to an existing AD. ...
    (microsoft.public.windows.server.sbs)
  • Re: force xp domain member to drop from domain?
    ... Right...but in this case, I never get to the credentials box...I change it to "workgroup", type in a workgroup name, click "OK", and then I get the modal that says the DC could not be contacted, and the only option is to "cancel" back to the first window. ... I also tried it at home in a set of virtual machines (Windows Server 2003 domain controller, ... Selected the Workgroup radio button, keyed "WORKGROUP", clicked OK, clicked OK on the credentials box - this was successful; after the restart the computer was no longer a domain member. ...
    (microsoft.public.windows.server.active_directory)
  • Re: force xp domain member to drop from domain?
    ... Don't know about any registry entry, but, with Vista in this scenario, you have to key something into the username and password box to escape from the credentials dialog box; you can key anything, but you have to key something before clicking OK. ... I've changed many computers from being in a domain to being in a workstation when the domain controller for the domain is not available and in every case, the Domain box is enabled, so your situation is unusual. ... I also tried it at home in a set of virtual machines (Windows Server 2003 domain controller, ... Selected the Workgroup radio button, keyed "WORKGROUP", clicked OK, clicked OK on the credentials box - this was successful; after the restart the computer was no longer a domain member. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Lost Domain Server and Password Failure
    ... First you need to make sure that the domain controller is configured ... itself as it's ONLY preferred dns server in tcp/ip properties via it's ... static IP address and them the clients must point to the domain controller ... them in a workgroup first before attempting to join the domain. ...
    (microsoft.public.win2000.security)

Quantcast