Role-based security from Windows Server 2003 Security Guide gives problems

Role-based security from Windows Server 2003 Security Guide gives problems

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Role-based security from Windows Server 2003 Security Guide gives problems Mikael Oskarsson 11-06-2006
Posted by Mikael Oskarsson on November 6, 2006, 7:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello


I have an Ad-environment with 2 Windows 2003 SP1 eng server and some Windows
2003 SP1 eng member server.
I have applied some EC-server policy from Microsoft document from april
2006.


On Domain root I have applied EC-Domain.inf
On Domain Controller OU I have applied EC-Domain Controller.inf
On Member Server OU I have applied EC-Member Server Baseline.inf
On sub OU Web OU I have applied EC-IIS server.inf

I joined 2 new web-servers to the domain and put them in the default
Computer OU. Lets call them lt104 and lt135 as servername.

Now my problems starts

If I from DC run My Computer > Manage > Connect to another computer, select
server104 see errors in word file.

If I from a member server that lies in Web OU run MBSA against all server
in the domain I get errors from scanning lt104 se word file

If I move the server lt104 to Web OU, none of the above errors occur. But
the server lt104 needs to connect to a standalone server to get picture and
I cant connect to that standalone server if lt104 is in the Web OU but it
works if it lies in Computer OU.


Any ideers whats causing this problem

Regards

Mikael



Posted by karl levinson, mvp on November 6, 2006, 8:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
> Windows 2003 SP1 eng member server.
> I have applied some EC-server policy from Microsoft document from april
> 2006.
>
> I joined 2 new web-servers to the domain and put them in the default
> Computer OU. Lets call them lt104 and lt135 as servername.
>
> If I from DC run My Computer > Manage > Connect to another computer,
> select server104 see errors in word file.
>
> If I from a member server that lies in Web OU run MBSA against all server
> in the domain I get errors from scanning lt104 se word file


The full and complete error message you are getting would be helpful. Also,
what happens when you search Google for that error message?


--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
--------------------------------
Microsoft Security FAQ:
http://securityadmin.info




Posted by Mikael Oskarsson on November 6, 2006, 8:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The errors from My Computer > Manage > Connect to another computer, is the
following:

Event viewer: "Unable to connect the computer "lt104" the error was. Access
is denied"
Local Users and Groups : "Unable to access the computer lt104: Access is
denied"
Services: "Unable to open service control manager database on lt104. Error
5: Access is denied"

MBSA says "An Unexpected error has occure.The operating system return error
code 1240"

Regards Mikael


>
>
>> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
>> Windows 2003 SP1 eng member server.
>> I have applied some EC-server policy from Microsoft document from april
>> 2006.
>>
>> I joined 2 new web-servers to the domain and put them in the default
>> Computer OU. Lets call them lt104 and lt135 as servername.
>>
>> If I from DC run My Computer > Manage > Connect to another computer,
>> select server104 see errors in word file.
>>
>> If I from a member server that lies in Web OU run MBSA against all server
>> in the domain I get errors from scanning lt104 se word file
>
>
> The full and complete error message you are getting would be helpful.
> Also, what happens when you search Google for that error message?
>
>
> --
> kind regards,
> Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
> --------------------------------
> Microsoft Security FAQ:
> http://securityadmin.info
>
>
>




Posted by Roger Abell [MVP] on November 6, 2006, 8:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Did you follow the advise in the guide and use the SCW (security
configuration wizard)? IOW is the W2k3 firewall in use?
Just as a note, the templates are intended as examples to be evaluated
and used as a basis from which one crafts the settings appropriate for
one's environment.
Why not use the GPMC modelling capability to see what settings
are effective for the webserver when it is in each of the two places,
the Web OU or the Computers container ??
Without our having access to view the specific policy settings in
use it is pretty hard to pin-point any specific settings that are in play
to cause the non-connectivities.



> Hello
>
>
> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
> Windows 2003 SP1 eng member server.
> I have applied some EC-server policy from Microsoft document from april
> 2006.
>
>
> On Domain root I have applied EC-Domain.inf
> On Domain Controller OU I have applied EC-Domain Controller.inf
> On Member Server OU I have applied EC-Member Server Baseline.inf
> On sub OU Web OU I have applied EC-IIS server.inf
>
> I joined 2 new web-servers to the domain and put them in the default
> Computer OU. Lets call them lt104 and lt135 as servername.
>
> Now my problems starts
>
> If I from DC run My Computer > Manage > Connect to another computer,
> select server104 see errors in word file.
>
> If I from a member server that lies in Web OU run MBSA against all server
> in the domain I get errors from scanning lt104 se word file
>
> If I move the server lt104 to Web OU, none of the above errors occur. But
> the server lt104 needs to connect to a standalone server to get picture
> and I cant connect to that standalone server if lt104 is in the Web OU but
> it works if it lies in Computer OU.
>
>
> Any ideers whats causing this problem
>
> Regards
>
> Mikael
>
>



Similar ThreadsPosted
Audit Privilege Use - Windows 2003 Security Guide April 3, 2008, 5:04 am
Windows 2003 server Network Security December 23, 2005, 3:20 pm
File Security in Windows Server 2003. April 24, 2006, 2:06 pm
Local Security rights Windows Server 2003 October 8, 2005, 1:57 pm
Windows 2003 Server Open File - Security Warning June 19, 2006, 11:59 am
Problems with SQL Server after installing security updates July 7, 2006, 10:02 am
Server 2003 Security Templates December 11, 2005, 1:46 pm
Security on 2003 Server Enterprise Edt. March 15, 2007, 1:38 pm
Unwrapping security on a 2003 server July 11, 2008, 11:03 am
Server 2003 DC Security Log Event 565 September 3, 2008, 3:32 pm

The site map in XML format XML site map

Contact Us | Privacy Policy