Click here to get back home

Security Templates

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security Templates Kevin Wheeler 12-28-2005
`--> Re: Security Templates Roger Abell [MV...12-29-2005
Get Chitika Premium
Posted by Kevin Wheeler on December 28, 2005, 7:09 am
Please log in for more thread options
How should security templates be layered? For example, I have a member
server template that is very restrictive. It really locks the server down.
Shouldn't I apply that first to a newly imaged server, then install the
application? (ie. Exchange 2003) I guess my concern is the User Rights
Assigments in the template. Is there a way for the accounts to be carried
to another server. From my experiences, all you get is SID numbers when you
apply the template to another computer.


Kevin



Posted by Steven L Umbach on December 28, 2005, 1:46 pm
Please log in for more thread options
To lock down a server you want to apply the security template first. Of
course this assumes that the security template has been tested so as to
allow the server to have the functionality it needs for the application. For
Windows 2003 you can also use secedit to create a rollback template of the
security template you want to apply and of course that needs to be done
before you apply the security template. The Windows 2003 Server Security
guide has specifics on how to lock down a Windows 2003 with baseline role
and specific server roles. For SP1 the Security Configuration Wizard may
also be a good option. You can not configure security templates with non
default local users/groups and expect them to work on another computer
because of the fact that the SID will not be the same on every computer
which is why you are seeing the results that you are. --- Steve

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/b1007de8-a11a-4d88-9370-25e244560587.mspx

--- secedit syntax
http://www.microsoft.com/windowsserver2003/technologies/security/configwiz/default.mspx

--- W2003 Security Configuration Wizard

> How should security templates be layered? For example, I have a member
> server template that is very restrictive. It really locks the server
> down.
> Shouldn't I apply that first to a newly imaged server, then install the
> application? (ie. Exchange 2003) I guess my concern is the User Rights
> Assigments in the template. Is there a way for the accounts to be carried
> to another server. From my experiences, all you get is SID numbers when
> you
> apply the template to another computer.
>
>
> Kevin
>
>



Posted by Roger Abell [MVP] on December 29, 2005, 9:56 am
Please log in for more thread options
Generally, if you first apply the template (apply it, not import it into
a GPO for application) and then do the install, you will find that
many installs will adjust things (user rights, etc.) so that the installed
will work. So, following the install, analyze the existing state against
the template that had been applied. This shows the changes made,
if any, to the templated settings by the install, and this allows you to
adjust the template to what is needed to accommodate the installed.
The adjusted template may then be appropriate for import into a
GPO for continuous enforcement.
When a template uses principals that are not well-knows with SIDs
that are everywhere the same, then yes, templates have a dependency
of the SAM of the SIDs. What I do is use a domain defined group
when possible to avoid the non-transportability of the templates, and
where that is inappropriate I simply edit the template to globally do
a replace of the machine specific SIDs with the counterparts on the
machine to which the template has been transported. (if you manually
alter one of the uses of the old with the new you get the new sid in
the notepad openable inf file)

> How should security templates be layered? For example, I have a member
> server template that is very restrictive. It really locks the server
> down.
> Shouldn't I apply that first to a newly imaged server, then install the
> application? (ie. Exchange 2003) I guess my concern is the User Rights
> Assigments in the template. Is there a way for the accounts to be carried
> to another server. From my experiences, all you get is SID numbers when
> you
> apply the template to another computer.
>
>
> Kevin
>
>



Similar ThreadsPosted
Security Templates June 23, 2005, 2:32 pm
security templates December 8, 2005, 12:19 pm
security templates January 29, 2006, 5:34 am
using security templates to harden servers July 24, 2007, 5:25 am
Security templates, problem with multiple settings July 26, 2005, 1:50 pm
SCW Templates December 20, 2006, 11:26 am
Securing with templates November 16, 2005, 3:58 am
Certificate templates with standalone CA October 7, 2005, 4:07 pm
Certificate Templates and third party CSP January 5, 2006, 8:11 am
SCEP and certificate templates June 11, 2006, 9:07 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap