Re: GPO extension

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi,

Johni schrieb:
Thanks you Mark. Let me please explain what I want to do.
[...]
We want to sign our application policies. On the server side, a hash
would be computed for each Group Policy Object, and signed by a
specifc person (not the AD admin).
On the client side, the signature is checked and the policies are only
applied if it is verified. [...]
Do you have an idea about how I can sign (and verify) my GPOs ? Do I
have to build a complete custom policy extension ?

Yes, because actual the client is not checking on certificates or
hashes at time the GPO is read and applied.

Simplif:
Today it´s a simple list, based on AD structure (OUs, dsacls, WMI) and
based on the GIUDs the client takes a look inside SYSVOL to read the
mentioned GPOs. Wether the GUID in AD nor the files in SYSVOL are
verified. It´s just reading LDAP and NTFS Filesystem.

If you want to change this, you need to change the winlogon.exe

If you only want to control your special application settings, but
none else, you ntegrate a new DLL as a CSE (winlogon.exe will call every
registered CSE) that is only applying your settings, if they are certified.

Mark
--
Mark Heitbrink - MVP Windows Server - Group Policy

Homepage: www.gruppenrichtlinien.de - deutsch
Discuss : www.freelists.org/list/gpupdate
.



Relevant Pages

  • Re: Policies having no effect on XP workstation
    ... The convergence time for GPOs can vary dramatically. ... > to the W2K3 server the policies started working. ... >>> opened up AD Users & Computers and could see the ...
    (microsoft.public.windows.group_policy)
  • Re: Group policys not applying
    ... This will depend on where you link the GPOs and the scope of the GPOs. ... I have setup a server to run as a pop3 email server ... I wish to use group policy to control the users computer when they log on to any machine in our network (5 workstations and 1 laptop) As part of the group policy i will control folder redirection to the server's larger hardrive. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SBS DCOM
    ... The doamin policies cahnged, but the local policies of the ... steps to reset the group policy objects to default, ... there are only 9 default group policies on the SBS server. ... Small Business Server Auditing Policy ...
    (microsoft.public.windows.server.sbs)
  • Re: Deploy using Group Policy - 100 printers = 100 GPOs!
    ... This is new in Server 2008 - we are still using Server 2003. ... consider using Group Policy Preferences - they give you equivalent ... My client deployed all printers using the Print Management Console / ... and all those GPOs are doing the same thing; ...
    (microsoft.public.windows.group_policy)
  • Re: get SUS up and running
    ... Go into the group policy for the domain/ou that you want it to apply to. ... tend to create new policies rather than modify existing ones (makes things ... right-click Administrative Templates and select Add/Remove Template. ... > to install alright on the windows2000 server I'm running. ...
    (microsoft.public.win2000.windows_update)