Re: GPO for trusted root CA certs
- From: briandel@xxxxxxxxxxxxxxxxxxxx (Brian Delaney [MSFT])
- Date: Fri, 10 Nov 2006 00:13:18 GMT
With which key is SMB signed?They key is derived from your authentication information. This key is used
to sign the SMB packets to prevent replay attacks.
With the server's RSA key from its server certificate?SMB signing is not based on any PKI technologies, no certificates are
required.
Have a look at these articles for more info on CIFS/SMB:
http://www.microsoft.com/technet/community/columns/secmgmt/sm0905.mspx
http://support.microsoft.com/kb/887429
Hope this helps,
Brian Delaney
Microsoft Canada
--
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Date: Fri, 10 Nov 2006 00:05:33 +0100Gecko/20060417
From: =?ISO-8859-1?Q?Michael_Str=F6der?= <michael@xxxxxxxxxxxx>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.13)
X-Accept-Language: en-us, en<8BsuGcpAHHA.5200@xxxxxxxxxxxxxxxxxxxxx>
MIME-Version: 1.0
Newsgroups: microsoft.public.windows.server.security
Subject: Re: GPO for trusted root CA certs
References: <8bd624-r0a.ln1@xxxxxxxxxxxxxxxx>
In-Reply-To: <8BsuGcpAHHA.5200@xxxxxxxxxxxxxxxxxxxxx>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Message-ID: <tqoc24-kqk.ln1@xxxxxxxxxxxxxxxx>
Brian Delaney [MSFT] wrote:
Michael Ströder wrote:
And how about protection of the network transport of GPO?
Are you referring to the application of a GPO over the network or
modifying?
Application of a GPO over the network.
As far as I know by default all that is done to secure both is
SMB signing is required on Windows Server 2003 SP1 (possibly RTM as well)
and can be set to required on Windows 2000. SMB signing helps to prevent
an SMB session from being highjacked once established.
With which key is SMB signed?
With the server's RSA key from its server certificate?
Ciao, Michael.
.
- References:
- GPO for trusted root CA certs
- From: Michael Ströder
- RE: GPO for trusted root CA certs
- From: Brian Delaney [MSFT]
- Re: GPO for trusted root CA certs
- From: Michael Ströder
- GPO for trusted root CA certs
- Prev by Date: Re: GPO for trusted root CA certs
- Next by Date: Re: Role-based security from Windows Server 2003 Security Guide gives problems
- Previous by thread: Re: GPO for trusted root CA certs
- Next by thread: Re: Audit - Summary of the folders and files
- Index(es):
Relevant Pages
|