Re: DHCP security breach
- From: "Jorge de Almeida Pinto [MVP]" <SubstituteThisWithMyFullNameSeparatedByDots@xxxxxxxxx>
- Date: Thu, 15 Jun 2006 23:15:20 +0200
all authenticated users can create RRs in DNS zones.
so if you configure your DHCP with a SIMPLE user account (not special) only
that account will be able to update the RRs (and all other security
principals in the ACL, which are admins and the DCs)
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
<boomboom999@xxxxxxxxx> wrote in message
news:1150350124.426194.91760@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Roger,
I agree with you that theoretically I can preserve integrity of
important DNS records by preventing DHCP from rewriting them. But in
practice, what can I do?
Microsoft recommends to run DHCP under a low privilege account.
I am wondering why Microsoft omits in their docs any recommendations on
ACL that this account must have on DNS zones.
Suppose, I have one zone with 4000 workstations and 300 servers. The
DHCP server acts under a specific AD account. I do not want to tweak
ACLs on every single record in my DNS zone.
What permissions should I give to the DHCP account on my DNS zone?
May be something like this?
Domain Computers = Create child objects
CREATOR/OWNER = Full Control
.
- References:
- DHCP security breach
- From: boomboom999
- Re: DHCP security breach
- From: Roger Abell [MVP]
- Re: DHCP security breach
- From: boomboom999
- DHCP security breach
- Prev by Date: Re: DHCP security breach
- Next by Date: Guided Help widget for MS Windows Malicious Software Removal Tool
- Previous by thread: Re: DHCP security breach
- Next by thread: Re: DHCP security breach
- Index(es):
Relevant Pages
|
|