Windows Server 2008 R2, Windows Server 2008, Windows Server 2003 ¹× Windows 2000 Server¿¡¼­ Gpo¿¡ ±âº» »ç¿ë ±ÇÇÑÀ» º¯°æ ÇÏ´Â ¹æ¹ý

±â¼ú ÀÚ·á: 321476 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¿ä¾à

±×·ì Á¤Ã¥ °³Ã¼ (Gpo) ¸ðµÎ¸¦ ¹æÁö Çϱâ À§ÇØ ½Å·ÚÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±×·ì¿¡ ±×·ì Á¤Ã¥ º¯°æ¿¡ ´ë ÇÑ º¸¾ÈÀ» °­È­ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·ì Á¤Ã¥ ÄÁÅ×ÀÌ³Ê classScema °³Ã¼ÀÇ DefaultSecurityDescriptor Ư¼ºÀ» ¼öÁ¤ ÇÏ ¿© ±×·¸°Ô ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯³ª º¯°æ¿¡¸¸ »õ·Î ¸¸µç gpo°¡ Àû¿ë µË´Ï´Ù. ±âÁ¸ Gpo¿¡ ´ë ÇÑ ±ÇÇÑ ±×·ì Á¤Ã¥ ÄÁÅ×À̳ʿ¡¼­ Á÷Á¢ ¼öÁ¤ °¡´É (CN = {GPO_GUID}, CN ½Ã½ºÅÛ, DC = µµ¸ÞÀÎ... =) ¹× ±×·ì Á¤Ã¥ ÅÛÇø´ (\\domain\SYSVOL\Policies\{GPO_GUID)}. ÀÌ ÀýÂ÷ ¶ÇÇÑ °ü¸® ÅÛÇø´ (ADM ÆÄÀÏ)¿¡ ±×·ì Á¤Ã¥ ÅÛÇø´À» ½Ç¼ö·Î °ü¸® µÇÁö ¾Ê´Â ¿öÅ©½ºÅ×À̼ǿ¡¼­ ADM ÆÄÀÏ ¾÷µ¥ÀÌÆ® µÇ °í¿¡¼­ ¹æÁöÇÒ ¼ö ÀÖ½À´Ï´Ù.

Ãß°¡ Á¤º¸

Active Directory °³Ã¼¸¦ »õ·Î ¸¸µé¸é DefaultSecurityDescriptor ½ºÅ°¸¶ÀÇ classSchema °³Ã¼ ÀÇ Æ¯¼º¿¡ ÁöÁ¤ µÈ ±ÇÇÑÀº Àû¿ë µË´Ï´Ù. GPO »ý¼º µÇ ¸éÀÌ ÀÎÇØ ÇØ´ç ÀÔ·Â °³Ã¼°¡ ÇØ´ç ACL DefaultSecurityDescriptor Ư¼º¿¡¼­ ¹Þ½À´Ï´Ù´Â CN ±×·ì Á¤Ã¥-ÄÁÅ×ÀÌ³Ê CN = ½ºÅ°¸¶, CN = ±¸¼º, DC = forestroot... = °³Ã¼ÀÔ´Ï´Ù. ±×·ì Á¤Ã¥ ÆíÁý±âµµ Æú´õ, ÇÏÀ§ Æú´õ ¹× ÆÄÀÏ¿¡´Â ±×·ì Á¤Ã¥ ÅÛÇø´ ({GPO_GUID} SYSVOL\Policies\)¿¡ ÀÌ·¯ÇÑ ±ÇÇÑÀ» Àû¿ëÇÕ´Ï´Ù.

DefaultSecurityDescriptor ±×·ì Á¤Ã¥ ÄÁÅ×À̳ÊÀÇ classSchema °³Ã¼¿¡ ´ë ÇÑ Æ¯¼ºÀ» ¼öÁ¤ ÇÏ·Á¸é ´ÙÀ½ ÇÁ·Î¼¼½º¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ½ºÅ°¸¶ º¯°æ À̹ǷΠÀüü º¹Á¦´Â ¸ðµç Gc¿¡ ´ë ÇÑ Æ÷¸®½ºÆ® Àüü¿¡ °ÉÃÄ ÇÏ ¿© ½ÃÀÛ µË´Ï´Ù. ½ºÅ°¸¶ »ç¿ë ±ÇÇÑ º¸¾È ¼³¸íÀÚ Á¤ÀÇ ¾ð¾î (SDDL)¸¦ »ç¿ë ÇÏ ¿© ÀÛ¼º µË´Ï´Ù. SDDL¿¡ ´ë ÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹® ÇϽʽÿÀ.
http://msdn2.microsoft.com/en-us/library/aa379567.aspx
±×·ì Á¤Ã¥ ÄÁÅ×À̳ÊÀÇ classSchema °³Ã¼ÀÇ DefaultSecurityDescriptor Ư¼ºÀ» ¼öÁ¤ ÇÏ·Á¸é:
  1. Æ÷¸®½ºÆ® ½ºÅ°¸¶ ¸¶½ºÅÍ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯´Â ½ºÅ°¸¶ °ü¸®ÀÚ ±×·ìÀÇ ±¸¼º¿ø ÀÎ °èÁ¤À¸·Î ·Î±×¿Â ÇÕ´Ï´Ù.
  2. Mmc.exe¸¦ ½ÃÀÛ ÇÏ °í ½ºÅ°¸¶ ½º³ÀÀÎÀ» Ãß°¡ ÇÕ´Ï´Ù.
  3. Active Directory ½ºÅ°¸¶¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ ÇÑ ´ÙÀ½ ÀÛ¾÷ ¸¶½ºÅ͸¦ Ŭ¸¯ ÇÕ´Ï´Ù.
  4. Ŭ¸¯ ÀÌ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¼­ ½ºÅ°¸¶¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.¸¦ Ŭ¸¯ ÇÑ ´ÙÀ½ È®ÀÎÀ» Ŭ¸¯ ÇÕ´Ï´Ù.
  5. ADSI ÆíÁý±â¸¦ »ç¿ë ÇÏ ¿© ½ºÅ°¸¶ ¸í¸í ÄÁÅØ½ºÆ®¸¦ ¿­°í ´ÙÀ½À» ã½À´Ï´Ù´Â CN = ±×·ì Á¤Ã¥ ÄÁÅ×ÀÌ³Ê Çü½Ä°ú classSchema °³Ã¼ÀÔ´Ï´Ù.
  6. °³Ã¼ÀÇ ¼Ó¼ºÀ» È®ÀÎ ÇÏ °í defaultSecurityDescriptor Ư¼ºÀ» ã½À´Ï´Ù.
  7. ¾²±â ±ÇÇÑÀ» µµ¸ÞÀÎ °ü¸®ÀÚ¿¡ ´ë ÇÑ ¿£ÅÍÇÁ¶óÀÌÁî °ü¸®ÀÚ¸¸ ¾²±â ±ÇÇÑÀÌ ¼ö ÀÖµµ·Ï ºÙ¿©³Ö±â ´ÙÀ½ ¹®ÀÚ¿­ °ªÀ» Á¦°Å:
    D:P(A;CIÀÔ´Ï´Ù.RPLCLOLORC; ÀÖ½À´Ï´Ù.;A) (A;CIÀÔ´Ï´Ù.RPWPCCDCLCLOLORCWOWDSDDTSW;;EA) (A;CIÀÔ´Ï´Ù.RPWPCCDCLCLOLORCWOWDSDDTSW;;)(A; COCIÀÔ´Ï´Ù.RPWPCCDCLCLORCWOWDSDDTSW;;SY) (A;CIÀÔ´Ï´Ù.RPLCLORC;;AU) (OA;CIÀÔ´Ï´Ù.CR; edacfd8f-ffb3-11d1-b41d-00a0c968f939;AU)
    Ãß°¡ ±×·ì ¾²±â ±ÇÇÑÀ» ºÎ¿© ÇÏ·Á¸é ÀÌÀü ÅØ½ºÆ®ÀÇ ³¡¿¡ ´ÙÀ½ ÅØ½ºÆ®¸¦ Ãß°¡ ÇÕ´Ï´Ù.
    (A;CIÀÔ´Ï´Ù.RPWPCCDCLCLOLORCWOWDSDDTSW;;Group_SID)
    Note Group_SID »ç¿ë ±ÇÇÑÀ» ºÎ¿©ÇÒ ±×·ìÀÇ SIDÀÔ´Ï´Ù.

    Âü°í Windows Server 2003ÀÇ defaultSecurityDescriptor Ư¼º¿¡ µû¶ó ¹®ÀÚ¿­À» ºÙ¿© ³Ö½À´Ï´Ù.
    D:P(A;CIÀÔ´Ï´Ù.RPLCLOLORC; ÀÖ½À´Ï´Ù.;A) (A;CIÀÔ´Ï´Ù.RPWPCCDCLCLOLORCWOWDSDDTSW;;EA) (A;CIÀÔ´Ï´Ù.RPWPCCDCLCLOLORCWOWDSDDTSW;;)(A; COCIÀÔ´Ï´Ù.RPWPCCDCLCLORCWOWDSDDTSW;;SY) (A;CIÀÔ´Ï´Ù.RPLCLORC;;AU) (OA;CIÀÔ´Ï´Ù.CR; edacfd8f-ffb3-11d1-b41d-00a0c968f939;AU) (A;CIÀÔ´Ï´Ù.LCRPLORC;;ED)


    Âü°íDefaultSecurityDescriptor Ư¼º º¯°æ ¸ðµç ±âÁ¸ Gpo¿¡ ´ë ÇÑ º¸¾È ¼³¸íÀÚ¸¦ ¼öÁ¤ ÇÏÁö ¾Ê½À´Ï´Ù. ±×·¯³ª À§ÀÇ Àüü ¹®ÀÚ¿­À» »ç¿ë sdutil.exe °°Àº µµ±¸¿Í ÇÔ²²¿¡¼­ ±âÁ¸ Gpo¿¡´Â ACLÀ» ¹Ù²Ü ¼ö ÀÖ½À´Ï´Ù.
  8. »õ ¹®ÀÚ¿­¿¡ ºÙ¿©³Ö±â¸¦ Ư¼º ÆíÁý »óÀÚ Àû¿ëŬ¸¯ ÇÏ °í ¼³Á¤À» Ŭ¸¯ ÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
Âü°íµµ¸ÞÀÎ °ü¸®ÀÚ ¶Ç´Â ¿£ÅÍÇÁ¶óÀÌÁî °ü¸®ÀÚ¿¡ ´ë ÇÑ ¾×¼¼½º¸¦ Á¦ÇÑ ÇÏ·Á´Â °æ¿ì ÀÔ·Â °³Ã¼´Â ±âº» ½ºÅ°¸¶ »ç¿ë ±ÇÇÑ °ÅºÎ¸¦ ¹èÄ¡ ÇØ¾ß ÇÕ´Ï´Ù. ¸¸µé¾îÁú ¶§ ÀÌ·¯ÇÑ ±×·ìÀº ±×·ì Á¤Ã¥ °³Ã¼¿¡ ACLÀ» addional¸¦ Ãß°¡ ÇÕ´Ï´Ù. µµ¸ÞÀÎ °ü¸®ÀÚ¿¡ ´ë ÇÑ Domain Admins¸¦ Ãß°¡ ÇØ¾ß ¹× ¿£ÅÍÇÁ¶óÀÌÁî °ü¸®ÀÚ °ü¸®ÀÚ¸¦ Ãß°¡ ÇÕ´Ï´Ù. °ÅºÎ Ãß°¡ restirict ÇÏ´Â À¯ÀÏÇÑ ¹æ¹ýÀº ÀÌ·¯ÇÑ ±×·ìÀÔ´Ï´Ù.

Microsoft WindowsÀÇ x64 ±â¹Ý ¹öÀü¿¡ ´ë ÇÑ ±â¼ú Áö¿ø

Çϵå¿þ¾î Á¦Á¶¾÷ü´Â WindowsÀÇ x64 ±â¹Ý ¹öÀü¿¡ ´ë ÇÑ ±â¼ú Áö¿øÀ» Á¦°øÇÕ´Ï´Ù. X64 ±â¹Ý ¹öÀüÀÇ Windows Çϵå¿þ¾î¿¡ Æ÷ÇÔ µÇ¾î Àֱ⠶§¹®¿¡ Çϵå¿þ¾î Á¦Á¶¾÷ü¿¡ Áö¿øÀ» Á¦°ø ÇÕ´Ï´Ù. Çϵå¿þ¾î Á¦Á¶¾÷ü °íÀ¯ ±¸¼º ¿ä¼Ò·Î windows ¼³Ä¡¸¦ »ç¿ëÀÚ ÁöÁ¤ ÇßÀ» ¼öµµ ÀÖ½À´Ï´Ù. °íÀ¯ ±¸¼º ¿ä¼Ò¸¦ ƯÁ¤ ÀåÄ¡ µå¶óÀ̹ö µîÀÌ ÀÖÀ» ¶Ç´Â Çϵå¿þ¾îÀÇ ¼º´ÉÀ» ÃÖ´ëÈ­ Çϱâ À§ÇÑ ¿É¼Ç ¼³Á¤ÀÌ Æ÷ÇÔ µÉ ¼ö ÀÖ½À´Ï´Ù. X 64 ±â¹Ý ¹öÀüÀÇ Windows¿Í ±â¼úÀûÀÎ µµ¿òÀÌ ÇÊ¿ä Çϸé Microsoft Áö¿ø ÇÕ¸®ÀûÀÎ Á¦°ø ÇÕ´Ï´Ù. ±×·¯³ª ÇØ´ç Á¦Á¶¾÷ü¿¡ Á÷Á¢ ¹®ÀÇ ÇØ¾ß ÇÕ´Ï´Ù. Á¦Á¶¾÷ü Á¦Á¶¾÷ü´Â Çϵå¿þ¾î¿¡ ¼³Ä¡ µÈ ¼ÒÇÁÆ®¿þ¾î¸¦ Áö ¿øÇÏ´Â µ¥ °¡Àå Á¤±ÔÈ­ µÈ.

Microsoft Windows XP Professional x64 Edition¿¡ ´ë ÇÑ Á¦Ç° Á¤º¸´Â ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹® ÇϽʽÿÀ.
http://www.microsoft.com/windowsxp/64bit/default.mspx
Á¦Ç° Á¤º¸¿¡ ´ë ÇÑ x 64 ±â¹Ý ¹öÀüÀÇ Microsoft Windows Server 2003¿¡¼­ ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹® ÇϽʽÿÀ.
http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx

¼Ó¼º

±â¼ú ÀÚ·á: 321476 - ¸¶Áö¸· °ËÅä: 2012³â 5¿ù 25ÀÏ ±Ý¿äÀÏ - ¼öÁ¤: 1.0
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Windows Server 2008 Standard
  • Windows Server 2008 Datacenter
  • Windows Server 2008 Enterprise
  • Windows Server 2008 for Itanium-Based Systems
  • Windows Server 2008 Foundation
  • Microsoft Windows Server 2003, Standard x64 Edition
  • Microsoft Windows Server 2003, Enterprise x64 Edition
  • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server
  • Windows Server 2008 R2 Standard
  • Windows Server 2008 R2 Enterprise
  • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 R2 for Itanium-Based Systems
  • Windows Server 2008 R2 Foundation
Ű¿öµå:?
kbenv kbgrppolicyinfo kbhowto kbmt KB321476 KbMtko
±â°è ¹ø¿ªµÈ ¹®¼­
Áß¿ä: º» ¹®¼­´Â Àü¹® ¹ø¿ª°¡°¡ ¹ø¿ªÇÑ °ÍÀÌ ¾Æ´Ï¶ó Microsoft ±â°è ¹ø¿ª ¼ÒÇÁÆ®¿þ¾î·Î ¹ø¿ªÇÑ °ÍÀÔ´Ï´Ù. Microsoft´Â ¹ø¿ª°¡°¡ ¹ø¿ªÇÑ ¹®¼­ ¹× ±â°è ¹ø¿ªµÈ ¹®¼­¸¦ ¸ðµÎ Á¦°øÇϹǷΠMicrosoft ±â¼ú ÀÚ·á¿¡ ÀÖ´Â ¸ðµç ¹®¼­¸¦ Çѱ۷ΠÁ¢ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯³ª ±â°è ¹ø¿ª ¹®¼­°¡ Ç×»ó ¿Ïº®ÇÑ °ÍÀº ¾Æ´Õ´Ï´Ù. µû¶ó¼­ ±â°è ¹ø¿ª ¹®¼­¿¡´Â ¸¶Ä¡ ¿Ü±¹ÀÎÀÌ Çѱ¹¾î·Î ¸»ÇÒ ¶§ ½Ç¼ö¸¦ ÇÏ´Â °Íó·³ ¾îÈÖ, ±¸¹® ¶Ç´Â ¹®¹ý¿¡ ¿À·ù°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. Microsoft´Â ³»¿ë»óÀÇ ¿À¿ª ¶Ç´Â Microsoft °í°´ÀÌ ÀÌ·¯ÇÑ ¿À¿ªÀ» »ç¿ëÇÔÀ¸·Î½á ¹ß»ýÇÏ´Â ºÎ Á¤È®¼º, ¿À·ù ¶Ç´Â ¼ÕÇØ¿¡ ´ëÇØ Ã¥ÀÓÀ» ÁöÁö ¾Ê½À´Ï´Ù. Microsoft´Â ÀÌ·¯ÇÑ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇØ ±â°è ¹ø¿ª ¼ÒÇÁÆ®¿þ¾î¸¦ ÀÚÁÖ ¾÷µ¥ÀÌÆ®Çϰí ÀÖ½À´Ï´Ù.
ÀÌ ¹®¼­ÀÇ ¿µ¹® ¹öÀü º¸±â:321476

Çǵå¹é º¸³»±â