Re: what is a 'secure' dynamic update (dns)

Tech-Archive recommends: Fix windows errors by optimizing your registry



.... and forgot to say thanks for the links. I will check them out.

"Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx> wrote in message
news:e3HYVbIKGHA.648@xxxxxxxxxxxxxxxxxxxxxxx
Secure updates mean that the principal that is updating the zone must have
permissions to do so. Basically, this means that the principal must be a
valid domain account that has authenticated with a DC.

Secure updates are only available on AD-Integrated zones because the zones
are container objects in the directory and each record is an object.
Permissions can be controlled - for example, Auth users can create,
CREATOR/
OWNER can modify and delete. Standard zones are simply text files.

Here is the resource kit documentation on secure DDNS:
--

http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit/en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/en-us/w2rkbook/default.asp

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net




.



Relevant Pages

  • Re: Moving DCs From Default OU ?
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... although I don't have permissions I can change them back so I ...
    (microsoft.public.windows.server.active_directory)
  • Re: CAS newbie
    ... The production web site is a two server ... If you are impersonating, then you will likely need to implement Kerberos ... Joe Kaplan-MS MVP Directory Services Programming ... code group to give full trust permissions to that dll. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: CAS newbie
    ... It appears that you may need to assert more than ... If you are impersonating, then you will likely need to implement Kerberos ... Joe Kaplan-MS MVP Directory Services Programming ... code group to give full trust permissions to that dll. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: AdminPak installed by Domain User - can view all tabs and grou
    ... Remember also that normal domain users can query the domain using LDAP with ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... The permissions to read the data isn't a risk. ... Is allowing non administrators use of ADUC a risk? ...
    (microsoft.public.windows.server.active_directory)
  • Re: More than 200 AD Security Groups
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Joe Kaplan-MS MVP Directory Services Programming ... also is permissions groups. ...
    (microsoft.public.windows.server.active_directory)