Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
All,
I have been looking for this. Does anyone know what this refers to?
And what applications this may break? Is it applied to DCs or to all
servers in a domain/forest? Is it specific to W2K or to W2K3 as well?
I have no more details other than the name is "AD Security Patch."
Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
Patty Calcaterra wrote:
> All,
>
> I have been looking for this. Does anyone know what this refers to?
> And what applications this may break? Is it applied to DCs or to all
> servers in a domain/forest? Is it specific to W2K or to W2K3 as well?
>
> I have no more details other than the name is "AD Security Patch."
Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
It is supposed to secure AD. I myself have never heard of such a
thing. Ever. However, the company also says it has broken other
applications, which makes me assume that the it is applied to all
servers and not just DCs. I am currently involved in deploying Unity
and they AD folks are concerned that their AD patch is going to cause
issues.
Now, I have asked the AD folks for more details but....heaven help me
for saying this....they are not very bright but extremely defensive and
think they know everything. I had to explain LDIF to them for all
their knowledge, though....
So, with this in mind, before I question them some more, I wanted
confirmation that this really existed. I did a dump on their patches
and none of them said "AD Security Patch". Heh. However, when pushed,
they said that ws the name of it and they had regrets for implementing
it.
Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
Patty Calcaterra wrote:
> It is supposed to secure AD. I myself have never heard of such a
(...)
I think that they don't know what they are talking about. There was no
security patch in last few months targeting spepcific Active Directory
and there was no patch with pourpose of AD hardening.
If they had some problems probably they run into some problems after one
of security patches but not AD specific.
These templates can break a ton things if not reviewed VERY carefully.
Other than that, tell their AD guru's they aren't guru's if they can't give
you a name other than 'AD Security Patch'. They should know better that all
patches are KB or Bulletins #'s. Coax the # out of them by telling them that
the MS06-099 is the fix for their problems. If they say "YES!", their
morons. If they say "No, it's ____", bingo, there's the number you need. :~>
Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
Heh, I will present the first three articles to them. These may be
handy. I need to review the patches they have installed versus these
articles you mention tomorrow. All I got from them is that the patch
broke some "stuff" but they couldn't really define the "stuff".
Regarding the Security Templates, that was the FIRST thing I thought
about when they said "Secure AD." So, I asked them if they did any
tweaks on their policies and I got a bunch of head scratching and then
a vehement NO! It's a patch! After speaking to them, I am thinking
that mentioning the NSA security docs would get some more head
scratching. And if it is in my power, they will never EVER know that
GPOs exist or that you can use them to secure more "stuff." They are
sweet boys and although a secure environment would be grand, it would
be like giving em beer and cattle prods.
Anyhow, I totally agree about these policies breaking a lot of things.
The hisec ones are really fun :-).
Snort-snort! MS06-099! I need to try that one! However, I already
know these fellas aren't gurus...I would call em goobs, sweet, gentle,
and clueless goobs. Heh.
I will keep ya posted on the findings.
Thanks again and thanks for the post, GeeB! I will forward the Patch
List on to them. I can trust them with that...policies are another
matter. :-)
Archived from groups: microsoft.public.windows.server.active_directory,microsoft.public.win2000.security (More info?)
Well, it appears they did have some of these "problematic" patches
installed, especially the second one (MS05-027). I reassured them that
this would not impact Unity, though. They were impressed that there
was more a name than AD Security Patch, too :-)...
Anyhow, we are a go extending the schema tonight.
Thanks again and your help was very much appreciated!
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.