Role-based security from Windows Server 2003 Security Guide gives problems

Role-based security from Windows Server 2003 Security Guide gives problems

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Role-based security from Windows Server 2003 Security Guide gives problems Mikael Oskarsson 11-06-2006
Posted by Mikael Oskarsson on November 6, 2006, 7:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello


I have an Ad-environment with 2 Windows 2003 SP1 eng server and some Windows
2003 SP1 eng member server.
I have applied some EC-server policy from Microsoft document from april
2006.


On Domain root I have applied EC-Domain.inf
On Domain Controller OU I have applied EC-Domain Controller.inf
On Member Server OU I have applied EC-Member Server Baseline.inf
On sub OU Web OU I have applied EC-IIS server.inf

I joined 2 new web-servers to the domain and put them in the default
Computer OU. Lets call them lt104 and lt135 as servername.

Now my problems starts

If I from DC run My Computer > Manage > Connect to another computer, select
server104 see errors in word file.

If I from a member server that lies in Web OU run MBSA against all server
in the domain I get errors from scanning lt104 se word file

If I move the server lt104 to Web OU, none of the above errors occur. But
the server lt104 needs to connect to a standalone server to get picture and
I cant connect to that standalone server if lt104 is in the Web OU but it
works if it lies in Computer OU.


Any ideers whats causing this problem

Regards

Mikael



Posted by karl levinson, mvp on November 6, 2006, 8:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
> Windows 2003 SP1 eng member server.
> I have applied some EC-server policy from Microsoft document from april
> 2006.
>
> I joined 2 new web-servers to the domain and put them in the default
> Computer OU. Lets call them lt104 and lt135 as servername.
>
> If I from DC run My Computer > Manage > Connect to another computer,
> select server104 see errors in word file.
>
> If I from a member server that lies in Web OU run MBSA against all server
> in the domain I get errors from scanning lt104 se word file


The full and complete error message you are getting would be helpful. Also,
what happens when you search Google for that error message?


--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
--------------------------------
Microsoft Security FAQ:
http://securityadmin.info




Posted by Mikael Oskarsson on November 6, 2006, 8:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The errors from My Computer > Manage > Connect to another computer, is the
following:

Event viewer: "Unable to connect the computer "lt104" the error was. Access
is denied"
Local Users and Groups : "Unable to access the computer lt104: Access is
denied"
Services: "Unable to open service control manager database on lt104. Error
5: Access is denied"

MBSA says "An Unexpected error has occure.The operating system return error
code 1240"

Regards Mikael


>
>
>> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
>> Windows 2003 SP1 eng member server.
>> I have applied some EC-server policy from Microsoft document from april
>> 2006.
>>
>> I joined 2 new web-servers to the domain and put them in the default
>> Computer OU. Lets call them lt104 and lt135 as servername.
>>
>> If I from DC run My Computer > Manage > Connect to another computer,
>> select server104 see errors in word file.
>>
>> If I from a member server that lies in Web OU run MBSA against all server
>> in the domain I get errors from scanning lt104 se word file
>
>
> The full and complete error message you are getting would be helpful.
> Also, what happens when you search Google for that error message?
>
>
> --
> kind regards,
> Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
> --------------------------------
> Microsoft Security FAQ:
> http://securityadmin.info
>
>
>




Posted by Roger Abell [MVP] on November 6, 2006, 8:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Did you follow the advise in the guide and use the SCW (security
configuration wizard)? IOW is the W2k3 firewall in use?
Just as a note, the templates are intended as examples to be evaluated
and used as a basis from which one crafts the settings appropriate for
one's environment.
Why not use the GPMC modelling capability to see what settings
are effective for the webserver when it is in each of the two places,
the Web OU or the Computers container ??
Without our having access to view the specific policy settings in
use it is pretty hard to pin-point any specific settings that are in play
to cause the non-connectivities.



> Hello
>
>
> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
> Windows 2003 SP1 eng member server.
> I have applied some EC-server policy from Microsoft document from april
> 2006.
>
>
> On Domain root I have applied EC-Domain.inf
> On Domain Controller OU I have applied EC-Domain Controller.inf
> On Member Server OU I have applied EC-Member Server Baseline.inf
> On sub OU Web OU I have applied EC-IIS server.inf
>
> I joined 2 new web-servers to the domain and put them in the default
> Computer OU. Lets call them lt104 and lt135 as servername.
>
> Now my problems starts
>
> If I from DC run My Computer > Manage > Connect to another computer,
> select server104 see errors in word file.
>
> If I from a member server that lies in Web OU run MBSA against all server
> in the domain I get errors from scanning lt104 se word file
>
> If I move the server lt104 to Web OU, none of the above errors occur. But
> the server lt104 needs to connect to a standalone server to get picture
> and I cant connect to that standalone server if lt104 is in the Web OU but
> it works if it lies in Computer OU.
>
>
> Any ideers whats causing this problem
>
> Regards
>
> Mikael
>
>



Similar ThreadsPosted
Audit Privilege Use - Windows 2003 Security Guide April 3, 2008, 5:04 am
Windows 2003 server Network Security December 23, 2005, 3:20 pm
File Security in Windows Server 2003. April 24, 2006, 2:06 pm
RE: Windows 2003 Server security vs Red hat Linux March 11, 2005, 2:35 pm
Local Security rights Windows Server 2003 October 8, 2005, 1:57 pm
Windows Server 2003 Security Update Removal July 17, 2009, 9:32 am
a standard windows server 2003 security question July 27, 2009, 11:48 am
Windows 2003 Server Open File - Security Warning June 19, 2006, 11:59 am
Problems with SQL Server after installing security updates July 7, 2006, 10:02 am
Server 2003 Security Templates December 11, 2005, 1:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy