Re: GPO for trusted root CA certs



Brian Delaney [MSFT] wrote:
Michael Ströder wrote:

And how about protection of the network transport of GPO?

Are you referring to the application of a GPO over the network or
modifying?

Application of a GPO over the network.

As far as I know by default all that is done to secure both is
SMB signing is required on Windows Server 2003 SP1 (possibly RTM as well)
and can be set to required on Windows 2000. SMB signing helps to prevent
an SMB session from being highjacked once established.

With which key is SMB signed?
With the server's RSA key from its server certificate?

Ciao, Michael.
.



Relevant Pages

  • Re: GPO for trusted root CA certs
    ... And how about protection of the network transport of GPO? ... SMB signing is required on Windows Server 2003 SP1 ...
    (microsoft.public.windows.server.security)
  • Re: Intermittant GPO failure to apply
    ... Gigabit have blocked the GPO applied, ... fluctuates as the network adapter driver initializes and as the network ... |> Value Name: DisableDHCPMediaSense ...
    (microsoft.public.windows.server.sbs)
  • Re: SMB packet and secure channel signing
    ... You know, in all the times that you and I have the debate on SMB Signing, ... > Optionally you can do "if client agrees" and thus the signing will be ... > Just don't screw up in the process of disabling these suckers. ... SMB Signing puts a tag on each and every network packet ...
    (microsoft.public.windows.server.sbs)
  • RE: Create user that dont have access to domain
    ... If you are talking about PCs in public areas, ... listed below) and then restrict network object access using the GPO. ... Through a GPO or local policy? ...
    (microsoft.public.windows.server.active_directory)
  • Re: SMB signing problem with winXP
    ... In an SBS 2003 network with Windows XP workstations I did have ... It drove the client crazy because it hung ... >> SMB Signing in the Default Domain Policy and the Default Domain ... >> There is no problem with Disabling SMB Signing entirely. ...
    (microsoft.public.backoffice.smallbiz2000)