workgroup vs domain recommendation
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > workgroup vs domain recommendation




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    workgroup vs domain recommendation  
BLMuzzy


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-16-06 06:27 AM

Does anyone know the pros & cons of having public servers in a workgroup vs
in a domain? My situation is I have a couple Win2003 IIS servers, a SQL
server, and a document mgmt server (SQL + doc storage) that's also an Active
Directory DC. The latter is used for LDAP validation of user logons. The
firewall rules are pretty tight and only allow https into the IIS boxes. My
question concerns the security of having the servers in 1 domain vs in 1
domain with the IIS & SQL boxes in a separate workgroup.

The domain is attractive for simplifying user accounts and implementing
group policies. But the risk is if someone hacks a password, it's valid all
over the domain, not just on one box.

thanks,
Bob







[ Post a follow-up to this message ]



    Re: workgroup vs domain recommendation  
David Wang [Msft]


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-16-06 06:27 AM

How about running the public servers in one public domain, your intranet
uses a second private domain, and only set up one-way trust between your
public and private domains so that you can use private domain account to
manipulate public servers (to prop out updates), but public accounts have no
rights on private domain machines.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

"BLMuzzy" <bob.muzzy@planitax.com> wrote in message
news:uBLqPMOkGHA.2436@TK2MSFTNGP03.phx.gbl...
> Does anyone know the pros & cons of having public servers in a workgroup
> vs in a domain? My situation is I have a couple Win2003 IIS servers, a SQL
> server, and a document mgmt server (SQL + doc storage) that's also an
> Active Directory DC. The latter is used for LDAP validation of user
> logons. The firewall rules are pretty tight and only allow https into the
> IIS boxes. My question concerns the security of having the servers in 1
> domain vs in 1 domain with the IIS & SQL boxes in a separate workgroup.
>
> The domain is attractive for simplifying user accounts and implementing
> group policies. But the risk is if someone hacks a password, it's valid
> all over the domain, not just on one box.
>
> thanks,
> Bob
>







[ Post a follow-up to this message ]



    Re: workgroup vs domain recommendation  
BLMuzzy


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-16-06 06:31 PM

Humm.  That sounds pretty intriguing; reasonable security plus no need for
duplicate user accounts.  The issue of one ID/pwd accessing multiple boxes
remains but is probably minimized.  thanks!


"David Wang [Msft]" <someone@online.microsoft.com> wrote in message
news:%23UVBuuOkGHA.4284@TK2MSFTNGP05.phx.gbl...
> How about running the public servers in one public domain, your intranet
> uses a second private domain, and only set up one-way trust between your
> public and private domains so that you can use private domain account to
> manipulate public servers (to prop out updates), but public accounts have
> no rights on private domain machines.
>
> --
> //David
> IIS
> http://blogs.msdn.com/David.Wang
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
> //
>
> "BLMuzzy" <bob.muzzy@planitax.com> wrote in message
> news:uBLqPMOkGHA.2436@TK2MSFTNGP03.phx.gbl... 
>
>







[ Post a follow-up to this message ]



    Re: workgroup vs domain recommendation  
David Wang [Msft]


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-17-06 12:19 AM

No problems. Using multiple domains with one-way AD trust relationship is
standard solution for this.

This way, any DMZ exploits of DMZ Domain accounts stay in the DMZ, which by
definition are ok with this.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

"BLMuzzy" <bob.muzzy@planitax.com> wrote in message
news:eSLvB5VkGHA.4284@TK2MSFTNGP05.phx.gbl...
> Humm.  That sounds pretty intriguing; reasonable security plus no need for
> duplicate user accounts.  The issue of one ID/pwd accessing multiple boxes
> remains but is probably minimized.  thanks!
>
>
> "David Wang [Msft]" <someone@online.microsoft.com> wrote in message
> news:%23UVBuuOkGHA.4284@TK2MSFTNGP05.phx.gbl... 
>
>







[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 12:41 PM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register