RE: Windows Active Directory Domains
Michael Sturtz <[email protected]> Wed, 9 Jul 2014 14:18:06 +0000
| Newsgroups | gmane.comp.security.basics |
|---|---|
| Message-ID | <B9D88FB1D162D243A22919FE9CFDE3341D14F109@ITDRENMX03.na.paccar.com> |
Having a separate AD forest gives the illusion of additional security. It = is not more secure. All people in the same organization should be in the s= ame AD forest. Protecting HR data can and should be done at the server lev= el and with modern Windows servers configured properly can not only prevent= unwanted access you can also audit that access in a central location such = as a command center. Having a separate forest greatly complicates your des= ign and could actually weaken the security of the HR data. If you want mor= e information feel free to PM me. =20 Thanks, Michael=20 -----Original Message----- From: [email protected] [mailto:[email protected]] On= Behalf Of [email protected] Sent: Tuesday, July 08, 2014 1:48 PM To: [email protected] Subject: Windows Active Directory Domains I have a scenario where I am trying to evaluate the security benefits of an= Active Directory domain structure. We will call the company XYX Inc. They have an AD Forest/Domain for general= users. They also have a separate AD Forest/Domain for their HR Users that = is behind a firewall.=20 The claim is that the separate forests with a one way trust provides the ne= cessary security to protect the HR Information. =20 My thinking is that having the users/servers in the same forest would provi= de additional benefit of ease of use for the technical team. Using the alre= ady existing firewall, separate the servers behind the firewall for the nee= ded protection of HR files. Before I make a recommendation of one way or the other, I wanted to elicit = the ideas of others who may have seen similar situations.=20 Thanks Joe Brown ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we= examine the importance of Apache-SSL and who needs an SSL certificate. We= look at how SSL works, how it benefits your company and how your customers= can tell if a site is secure. You will find out how to test, purchase, ins= tall and use a thawte Digital Certificate on your Apache web server. Throug= hout, best practices for set-up are highlighted to help you ensure efficien= t ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f72= 7d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------