|
Auditing Security Events
Hey guys is there a way for a simplified interpretation of security events in
windows 2003.
--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/200705/1
...
|
2 |
13.05.2007 19:27:02 |
|
Windows Vista Group Policies in a Server 2003 SP1 Domain environment
OK, so we run a Windows Server 2003 domain (Thats the functional
level) with servers all being at Server 2003 SP1. We are about to
begin looking at using Vista in our domain and I'm trying to figure
out how to Manage the additional group policies that are now available
with Vista. I just finished reading the following article in TechNet
(http://technet2.microsoft.com/WindowsVista/en/library...
|
1 |
11.05.2007 13:21:24 |
|
do allowed perrmisions override denyed permissions?
If a user on my Windows Server 2003 SBS domain is a member of 2 different
security groups that have overlapping permissions, would the allowed
permissions of one security group override the denied permissions of the
other security group? Or would the denied permissions override the allowed
permissions?
Though it may not be as cut and dry as that. Does the scope of the security
group...
|
18 |
10.05.2007 23:06:59 |
|
Location of SFPCOPY.EXE Utility?
This is in regard to the issue I posted here:
http://groups.google.com/group/microsoft.public.windows.server.security/browse_thread/thread/5445d002a051a96f/35ed79bc6950f4ec?lnk=st&q=%22windows+media+player+remote+code+execution%22&rnum=2#35ed79bc6950f4ec
Microsoft is telling me that a workaround for this issue would be to rename,
delete or move the un-patched version of WMP6.4 binary (dxmasf...
|
2 |
10.05.2007 15:37:29 |
|
using policy modules with Enterprise CA
Why MS doesn't allow to use your oun policy module?
> An enterprise certification authority should use only the
Microsoft-provided enterprise policy module.
Enterprise CA gives us ability to use different authentication
algorithms, but why there are so strong restrictions on policy modules?
Can we implement some steps and from Standart CA with my custom policy
module get all the features ...
|
1 |
10.05.2007 13:34:36 |
|
Windows service denied access to mapped drive
Hi
I have a windows service that monitors files on windows and unix
servers. Reflections NFS is installed and the UNIX paths are mapped
to drives. On my developer machine (XP) the service runs as expected
and can see the mapped unix drives.
After installing the service on Windows 2003 server SP1, the service
can no longer see the mapped drives, the error message returned is:
Could not...
|
5 |
10.05.2007 02:16:34 |
|
Tracking changes in ISS
Hello everyone. I am new to this site. I'm trying to find out how we can
track changes in ISS such as as when the changes were made and who made the
changes. Can anyone please help? thanks
...
|
1 |
09.05.2007 20:13:22 |
|
Critical security hotfix causes event log warnings
I started getting Application warnings shortly after I installed the
critical hotfix KB 925902 on my SBS 2000 server and restarted. They
continued every 5 minutes apart until I uninstalled the hotfix a week later.
Troubleshooting articles I found all suggested that the cause was some form
of corruption in the security database. As directed, I ran "esentutl.exe /q
C:\WINNT\security\datab...
|
7 |
09.05.2007 02:04:03 |
|
How to create a user with access to one server only.
Hi,
I would like to create a domain-wide user account with almost no rights at
all, except to use a web server inside a firewall.
The reason, is to manage the user in the AD, but have the user behave like a
local user account on a specified machine.
I am running a windows server 2003 and Active Directory.
Is it possible to create a Domain User Group that has no access at all, if
so...
|
6 |
09.05.2007 01:38:29 |
|
Group Policy
How cain i create new GP on Windows 2000 Server?
.. new domain controller group policy
.. new domain group policy
I have Problem with ID 1000
This error:
http://www.eventid.net/display.asp?eventid=1000&eventno=6866&source=Userenv&phase=1
Windows cannot access the file gpt.ini for GPO. The file must be present at
the location <>. (). Group Policy processing aborted.
...
|
3 |
08.05.2007 08:10:09 |
|
2 accounts point to 1 profile in W2K3
Has anyone ever had the follwing happen:
When you open the 'local users and group' manager on a server (which
is not part of a domain) the list of users is empty, even though when
using NET USER they all show up.
Moreover there seem to be two accounts pointing to one and the same
profile.
When doing a net users they show up as name1 and name2, and when
individually queried (NET USER nam...
|
2 |
07.05.2007 04:47:22 |
|
application monitoring
Hello, I am informing you people about a free program that makes you
tension free through checking processes in your system comparing their
signatures
continuously with a signature file that you have generated first. It
will alert whenever they change and when a new program runs.
This is meant for knowledgeable people. Download it only if you know
what you are doing.
Thanks.
http://bapul...
|
1 |
06.05.2007 21:11:44 |
|
EFS Unknown Error 0000177c
When I apply a new encrypt folder or file on map drive, it produces an error
message saying Error Applying Attributes, An error occurred applying
attributes to the file: P:\\Private\New Folder Unknown Error (0x0000177c)
click ignore, ignore all retry or cancel.
Anyone helps?...
|
1 |
05.05.2007 22:39:01 |
|
About EFS and local certificate that I want to export
Hello,
I have test something but I am not sure that I am right !
I have two computers XP_A and XP_B member of an active directory domain
with no certificate authority.
There are two users : Pascal and Isabelle.
1. Pascal logs on XP_A and encrypt a file with EFS.
2. Pascal exports his certificate through Internet explorer (with or
without the private key, the issue will be the same)
...
|
3 |
05.05.2007 12:18:22 |
|
Transition from a single enterprise CA to a tiered CA
We currently have a single Enterprise Certificate Authority installed on a
domain controller. After reading about best practices, I gather that this
is not really the right way to do it. (Plus I do not like being stuck with
this DC, if we needed to rebuild or remove it.)
I would like to set up an offline standalone root along with one or two
subordinate enterprise CAs. (For the numbe...
|
1 |
03.05.2007 16:38:57 |
|
Enable HTTP Connectivity
Hi All,
Is there anyone know how to Enable HTTP conectivity using IIS windows server
2003 ?
Thanks
Firman
...
|
3 |
02.05.2007 13:06:08 |
|
Svchost, DCOM, WMI Issues after Updates
Hello group,
I am tracking an issue on several Windows 2003 servers. The timeframe
roughly correlates with this month's patch cycle. I have not nailed it
down to one particular update, however. Is anyone seeing a similar
problem?
The symptoms include:
1) Svchost.exe has an exception and stops. All of the services running
under it close. The services affected include:
Automatic Upda...
|
3 |
02.05.2007 12:51:58 |
|
Domain logoff vs. shutdown
am trying to understand if it is ok to do a machine shutdown instead of a
domain logoff. We would like everyone to logoff their domain account each
day, but many just shutdown their computers. Does a shutdown do an orderly
domain logoff?...
|
3 |
01.05.2007 05:05:07 |
|
Certificates trouble: CRL not available(?) and "revocation server offline" error
Hello to all!!!
I had installed EntRoot and EntIssuing CAs for my test environment
(they are both online), and after that configured them like this:
EntRoot
- CDP and AIA locations left on default.
- Base CRL publication is 1 week, no Delta CRLs.
- Deleteted all cert tmpls from CA>Certificate Templates except
Subordinate Certification Authority.
EntIssuing
- CDP and AIA location...
|
4 |
01.05.2007 02:56:48 |
|
Security Issue/Question
All,
I have updated a couple users that used to belong to the administrators
group. I have removed them, mainley due to the Exchange Send As issue and
Blackberry's. It does not seem that the change in security is being updated
in Exchange becasue the users still have the send as issue. I have worked
with Blackberry to verify that the proper permission are added for the new
Blackber...
|
5 |
30.04.2007 14:59:01 |
|
antivirus for 64 bit windows
anyone can suggest a good antivirus program for a small office network
running win2003 server 64 bit with exchange 2007?
Thanks
---
Ed
...
|
2 |
29.04.2007 14:23:18 |
|
Firewall difference form exception and advanced setting serivce
What's the exactly difference between exception and avanced setting
service?
I mean, both allow to create a rule that leave some ports open.
Exception allow you to specify an executable (or something that can be
run) instead server IP, but why in most post I read create an
exception and then advanced setting service rule? For the test I did
just the last one is all is needed to leave the por...
|
1 |
28.04.2007 14:49:06 |
|
Changes in setup/configuration for VPN and IPSec??
VPN network:
- The additional VPN related setup/configuration is required only at
the entry/exit point of the network i.e. routers. No changes are
necessary on other machines/systems in that network.
IPSec network:
- Each machine/system in the network will need to have the additional
IPSec related setup/configuration.
Is that correct? Which one is preferred over the other, and in what...
|
2 |
26.04.2007 08:54:12 |
|
Hidding folder?
Hi, how are you doing?
I would like to know if is possible to creating a folder on Windows NTFS
partition, but this folder will be hidden from all users, including
administrators, system, and all top users, excepts to a user account wich I
will create wich will have total access to folder, so when I log on the
machine using the special user, the folder will be available, because I need ...
|
4 |
25.04.2007 14:17:19 |
|
User Profile Question
Hi,
I'm asking your kind help to understand and solve this problem:
I've been managing a Windows 2003 Server Domain with 30 users (with remote
profiles) for few months.
Some of these users are Administrators of their own computer.
Now I would set their local rights as "Power Users" so they will be not able
to install any unwanted software anymore.
After changed the local user rights fro...
|
2 |
24.04.2007 15:47:49 |