RE: Windows Active Directory Domains

Michael Sturtz <[email protected]> Wed, 9 Jul 2014 14:18:06 +0000
Newsgroups gmane.comp.security.basics
Message-ID <B9D88FB1D162D243A22919FE9CFDE3341D14F109@ITDRENMX03.na.paccar.com>
Having a separate AD forest gives the illusion of additional security.  It =
is not more secure.  All people in the same organization should be in the s=
ame AD forest.  Protecting HR data can and should be done at the server lev=
el and with modern Windows servers configured properly can not only prevent=
 unwanted access you can also audit that access in a central location such =
as a command center.  Having a separate forest greatly complicates your des=
ign and could actually weaken the security of the HR data.  If you want mor=
e information feel free to PM me. =20
Thanks,
Michael=20

-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of [email protected]
Sent: Tuesday, July 08, 2014 1:48 PM
To: [email protected]
Subject: Windows Active Directory Domains

I have a scenario where I am trying to evaluate the security benefits of an=
 Active Directory domain structure.

We will call the company XYX Inc. They have an AD Forest/Domain for general=
 users. They also have a separate AD Forest/Domain for their HR Users that =
is behind a firewall.=20

The claim is that the separate forests with a one way trust provides the ne=
cessary security to protect the HR Information. =20

My thinking is that having the users/servers in the same forest would provi=
de additional benefit of ease of use for the technical team. Using the alre=
ady existing firewall, separate the servers behind the firewall for the nee=
ded protection of HR files.

Before I make a recommendation of one way or the other, I wanted to elicit =
the ideas of others who may have seen similar situations.=20

Thanks

Joe Brown

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate In this guide we=
 examine the importance of Apache-SSL and who needs an SSL certificate.  We=
 look at how SSL works, how it benefits your company and how your customers=
 can tell if a site is secure. You will find out how to test, purchase, ins=
tall and use a thawte Digital Certificate on your Apache web server. Throug=
hout, best practices for set-up are highlighted to help you ensure efficien=
t ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f72=
7d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------