Re: Domain Controller and IIS, SQL Server or Exchange?

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 07/16/03


Date: Wed, 16 Jul 2003 13:52:27 GMT


On 15 Jul 2003 15:33:42 -0700, t_squared33@yahoo.com (T_Squared)
wrote:

>I have a question for all you gurus out there. If you are faced with
>installing IIS 5.0, SQL Server 2000 or Exchange (5.5 or 2000) on one
>of two Windows 2000 DC's, then which application would you choose.
>
>1.)Win 2K DC and IIS 5.0
>2.)Win 2K DC and SQL Server 2000
>3.)Win 2K DC and Exhange (5.5 or 2000)
>
>I know that it all can co-exist, I've done it in a test environment.
>However, when faced with a decision for a production environment of at
>most 25 users, which "co-habitation" scenario is the lesser of all
>evils from a security standpoint? ( I have to make a choice- help!)

You don't provide enough information to know. Is the IIS for internet
or intranet? Is the system inside or outside your firewall? What
kind of traffic, what types of applications, what is the hardware, how
many users and mail accounts, etc.?

>From a security standpoint, put nothing on a DC. Especially outward
facing. Plus there are issues with IIS on a DC where you have no
local accounts and everything is a domain account.

Jeff



Relevant Pages

  • Re: IIS folder structure and security.
    ... That's basic Windows security, not limited to IIS so a decent Windows ... >> In the IIS each site have it's root to the 'www' folder. ... >> Windows accounts and set NTFS permissions on each customers folder? ...
    (microsoft.public.inetserver.iis.security)
  • Re: bypass traverse checking
    ... Bypass traverse only means that an account does not need to have at least ... Consider, in your prior IIS 5 box, if for each website you have ... However, for IIS6 there are some new accounts to consider, and you do need ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.inetserver.iis.security)
  • Re: Domain Controller and IIS, SQL Server or Exchange?
    ... >of two Windows 2000 DC's, then which application would you choose. ... >I know that it all can co-exist, I've done it in a test environment. ... Plus there are issues with IIS on a DC where you have no ... local accounts and everything is a domain account. ...
    (microsoft.public.sqlserver.security)
  • SSL Newbe: http://YourWebServer/certsrv/ missing during setup
    ... Configure SSL in a Windows 2000 IIS 5.0 Test Environment by Using ... Certificate Server 2.0 ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: mod_auth for IIS 6
    ... >normal form with login and password. ... >on the server which are reachable without create iis accounts. ... Windows and IIS? ...
    (microsoft.public.inetserver.iis)