Re: Security Question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"supersonic_oasis" <supersonicoasis@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:94F9F28F-FBF1-4553-B9FD-E0CB5A9E2CBC@xxxxxxxxxxxxxxxx
Hello, I am running Active Directory on all Win2003 servers. I was
wondering
about the default security settings that are configred on the servers as
far
as communications between other servers in the domain, and the clients.

That is likely to broad a question for you to receive a definitive
answer -- some of your specific examples below are easy to
answer however....

For instance, are the comminications between the clients and the servers
encrypted?

In general, "No" but for authentication purposes you the opposite
is true and passwords are not exposed.

There are many kinds of "client-server communication" howerever
and most of these will not be encrypted by default. (E.g., File, print,
web, email, etc.)

If you wish to force/encourage encryption then consider implementing
IPSec (likely through a GPO) for (some of) your machines.

What is used to encrypt it?

The default authentication is done through a secure channel between
DC and Client computer, and will also invoke Kerberos if both sides
are running at least Win2000 -- Kerberos will never actually pass the
password across the wire.

SMB signing (but not encryption) is the default for Win2003 DCs,
and SMB encryption CAN be required by the DCs through a GPO
settings.

And is there anyplace in the GUI that
I can see these settings?

No, not really. (Except the GPO settings perhaps.)



.



Relevant Pages

  • Re: Unix Services / Default Permissions / WinXP_Pro
    ... File encryption can lead to a whole bunch of problems if not ... >> and configuration settings and completely reinstall the operating system ... >> Sitter, Net Nanny, or the Windows Shared Computer Toolkit to restrict the ...
    (microsoft.public.security)
  • Re: Disadvantages to peristing replication settings as text?
    ... I'd actually have the mobile app include a "settings" ... in the registry. ... derived the encryption algorithm. ...
    (microsoft.public.sqlserver.ce)
  • Re: Are Pipex slowing p2p?
    ... settings in Azureus, settings on the router or hardware. ... Have you tried turning on the encryption feature in the latest Azureus? ... I am still maxing at 24k now as I ... popular torrents as more people are likely to have the feauture turned on. ...
    (uk.telecom.broadband)
  • Re: Disadvantages to peristing replication settings as text?
    ... If you are talking about the eVB sample, I have actually used that signature ... encryption concept for awhile now -- but only for the signature. ... My app does include a "Replication Settings" form ... sounds like you have pretty much narrowed it down to the registry as the ...
    (microsoft.public.sqlserver.ce)
  • Unable to Encrypt Offline Files via GPO or registry & dont want to set manually
    ... I'm trying to apply the setting "Encrypt Offline Files to secure data" to ... Files cache Group Policy. ... with no other settings configured. ... confirmed that those who aren't showing encryption in the check box truly ...
    (microsoft.public.windows.group_policy)