The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Read-Only Domain Controller and Server Core
Time: 00:52 EST/05:52 GMT | News Source: *Linked Within Post* | Posted By: Kenneth van Surksum

By default, an Read Only DC doesn't actually store any passwords ("user secrets"). Not only that, but the replication is unidirectional so an RODC won't replicate any information back to the primary domain controller. These features in-turn reduce the attack surface of a Windows Server.

The story that is trying to be won with this new feature in this release is the Branch Office story. Basically, for a company that is large enough to have branch offices (where physical security might not be as strong), instead of deploying a fully blown domain controller, you can now deploy a read-only domain controller. This ensures that if the remote domain controller is compromised, that the entire AD forest is not compromised (since by default, there is very little chance that a username/password combination is cached that could be used to compromise the rest of the domain). Combine this new features with the new "Server Core" installation option, and you come one step closer to a true "domain appliance." What is Server Core? Server Core is an install path of Longhorn Server (as of Beta 2) that does not install the unnecessary components of the OS (like the GUI or applications like Internet Explorer (after all, why in the world would I need Internet Explorer on a Server?!?!?)). Not only does this further reduce the attack surface of Windows Server, it also will minimize the amount of patching and maintenance that is required. This is something that the Linux/Unix servers have been doing great for a while, so I'm happy to see Windows Server finally catching up in this space!

Write Comment
Return to News

  Displaying 201 through 202 of 202
Prev | First
  The time now is 10:26:53 PM ET.
Any comment problems? E-mail us
#201 By 4240821 (62.76.153.72) at 8/27/2024 2:17:34 AM
https://sexonly.top/gett/c452/c452qdkmdmsjawufkao.php
https://nsfw.su/get/a49/a49zsbkkuswkfblekx.php
https://sexonly.top/gett/c519/c519sijqseenngqxaeq.php
https://sexonly.top/gett/c0/c0olzrzjzyjqhrrzq.php
https://sluts.su/get/a53/a53sjovzvzslwsqcjw.php
https://sexonly.top/gett/c389/c389oxmbhahuclpbojl.php
https://sexonly.su/get/a234/a234uhrflzlysoszorj.php
https://sexonly.top/gett/c894/c894gaujmhyecifpcen.php
https://sexonly.top/gett/c938/c938bjxhilsjeneszqe.php
https://sexonly.top/gett/c579/c579hudxcnuzrgihfxy.php

#202 By 4240821 (80.73.244.53) at 8/27/2024 11:32:23 AM
https://bio.site/flypadnori546
https://bio.site/travanvelraft168
https://bio.site/jaymacomcoa944
https://bio.site/tiolandlaba359
https://bio.site/bracmopora193
https://bio.site/udperfamel859
https://bio.site/pietagoldta489
https://bio.site/eruranvi964
https://bio.site/waismarraiquad654
https://bio.site/vieriemedtang510

Write Comment
Return to News
  Displaying 201 through 202 of 202
Prev | First
  The time now is 10:26:53 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *