Re: CasPol security

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Chris Botha (chris_s_botha_at_AT_h.o.t.m.a.i.l.com)
Date: 05/25/04


Date: Tue, 25 May 2004 19:24:44 -0400

My humble opinion, I gave our whole server full trust on all desktops. It is
locally on the Intranet, any non-dotnet app on the server can be executed
from any desktop without a hoot in any case and I don't have time to try and
figure out what the minimum trust level per application should be.
This kind of issue is important when you use no-touch deployment over the
internet, as you are loading an app from a foreign server, not that I've
stumbled upon one on some Internet site yet, but just in case.

<anonymous@discussions.microsoft.com> wrote in message
news:11dba01c44251$77d1aa30$a301280a@phx.gbl...
> Whats the danger in doing:
>
> C:\...\caspol -enterprise -addfulltrust L:\foo.exe
>
> foo is a local network (non-web based) application that
> references internal databases and general web based
> information sites.
>
> Steve



Relevant Pages

  • Re: Trust requirements for TS License Server in a different domain
    ... Licensing Server needs to trust the domain containing the Terminal ... only thinking about the Terminal Server and the TS Licensing ... have to be in trust relationship with License Server Domain ...
    (microsoft.public.windows.terminal_services)
  • Re: New Desktops AND new SBS 2003 R2 Install - Need Migration Help
    ... In moving the My Documents folder from the Desktops to the Users Shared ... All files are to move to the server for the ... acting as a pseudo-server for NOD32 Antivirus and our Accounting Software. ...
    (microsoft.public.windows.server.sbs)
  • RE: VBScript: Remote Desktop Disconnected
    ... Thank you for posting to the SBS Newsgroup. ... I understand that you cannot access server and client workstations desktops ... Internet remote computers. ...
    (microsoft.public.windows.server.sbs)
  • Re: Not able to establish trust with another window 2003 domain
    ... The time of the two server is the same. ... MVP - Directory Services ... I had follow exactly the same that stated in your article but still fail. ... I try to remove the trust that created at my Source and re-create again. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cannot connect to desktops on LAN using RWW or RDC
    ... Microsoft CSS Online Newsgroup Support ... but you can RDP to the server. ... >> Users cannot connect to remote desktops by using the Windows Small ...
    (microsoft.public.windows.server.sbs)