À§ÀÓµÈ »ç¿ë ±ÇÇÑÀ» »ç¿ëÇÒ ¼ö ¾øÀ¸¸ç »ó¼ÓÀÌ ÀÚµ¿À¸·Î ÇØÁ¦µÈ´Ù

±â¼ú ÀÚ·á: 817433 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

Çö»ó

Microsoft Windows Server 2003À¸·Î ¾÷±×·¹À̵åÇÏ¸é ´ÙÀ½°ú °°Àº Çö»óÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • Á¶Á÷ ±¸¼º ´ÜÀ§ÀÇ ¸ðµç »ç¿ëÀÚ°¡ À§ÀÓµÈ »ç¿ë ±ÇÇÑÀ» »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.
  • ÇÑ ½Ã°£¿¡ ÇÑ ¹ø Á¤µµ¾¿ ÀϺΠ»ç¿ëÀÚ °èÁ¤¿¡¼­ »ó¼ÓÀÌ ÀÚµ¿À¸·Î »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤µË´Ï´Ù.
  • ÀÌÀü¿¡ »ç¿ë ±ÇÇÑÀ» À§ÀÓÇÑ »ç¿ëÀÚ°¡ ´õ ÀÌ»ó ÇØ´ç »ç¿ë ±ÇÇÑÀ» °®°í ÀÖÁö ¾Ê½À´Ï´Ù.
ÀÌ ¹®Á¦´Â Microsoft ±â¼ú ÀÚ·á ¹®¼­ 327825¿¡¼­ ¼³¸íÇÏ´Â ÇÖÇȽº¸¦ Microsoft Windows 2000 Server¿¡ Àû¿ëÇÑ Èijª Windows 2000 ¼­ºñ½º ÆÑ 4¸¦ Microsoft Windows 2000 Server¿¡ ¼³Ä¡ÇÑ ÈÄ¿¡µµ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. Windows 2000 327825 ÇÖÇȽº¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
327825 »ç¿ëÀÚ°¡ ¿©·¯ ±×·ì¿¡ ¼ÓÇØ ÀÖ´Â °æ¿ìÀÇ Kerberos ÀÎÁõ ¹®Á¦¿¡ ´ëÇÑ »õ·Î¿î ÇØ°á ¹æ¹ý

¿øÀÎ

Á¦¾î À§ÀÓ ¸¶¹ý»ç¸¦ »ç¿ëÇÏ¿© »ç¿ë ±ÇÇÑÀ» À§ÀÓÇÏ´Â °æ¿ì ÇØ´ç »ç¿ë ±ÇÇÑÀº ºÎ¸ð ÄÁÅ×À̳ʿ¡¼­ »ç¿ë ±ÇÇÑÀ» »ó¼ÓÇÏ´Â »ç¿ëÀÚ °³Ã¼¿¡¸¸ Àû¿ëµË´Ï´Ù. º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀº ºÎ¸ð ÄÁÅ×À̳ʿ¡¼­ »ç¿ë ±ÇÇÑÀ» »ó¼ÓÇÏÁö ¾Ê½À´Ï´Ù. µû¶ó¼­ Á¦¾î À§ÀÓ ¸¶¹ý»ç¸¦ »ç¿ëÇÏ¿© »ç¿ë ±ÇÇÑÀ» ¼³Á¤Çϸé ÇØ´ç »ç¿ë ±ÇÇÑÀÌ º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿ø¿¡ Àû¿ëµÇÁö ¾Ê½À´Ï´Ù.

Âü°í º¸È£µÇ´Â ±×·ìÀÇ ±×·ì µî·ÏÀº Çϳª ÀÌ»óÀÇ º¸¾È ¶Ç´Â ¸ÞÀÏ ±×·ìÀ» »ç¿ëÇÏ´Â Á÷Á¢ ±×·ì µî·ÏÀ̳ª ÀüÀÌÀû ±×·ì µî·ÏÀ¸·Î Á¤Àǵ˴ϴÙ. ¸ÞÀÏ ±×·ìÀº º¸¾È ±×·ìÀ¸·Î º¯È¯µÉ ¼ö Àֱ⠶§¹®¿¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

Windows Server 2003¿¡¼­ º¸È£µÇ´Â ±×·ìÀÇ ¼ö´Â Active Directory¿¡¼­ º¸¾ÈÀ» °­È­Çϱâ À§ÇØ ´Ã¾î³µ½À´Ï´Ù("Ãß°¡ Á¤º¸" Àý ÂüÁ¶). Windows 2000¿¡ 327825 ÇÖÇȽº¸¦ Àû¿ëÇÏ´Â °æ¿ì¿¡µµ º¸È£µÇ´Â ±×·ìÀÇ ¼ö°¡ ´Ã¾î³³´Ï´Ù.

ÇØ°á ¹æ¹ý

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é ÇÖÇȽº¸¦ ¼³Ä¡ÇÏ¸é µË´Ï´Ù. °¢ µµ¸ÞÀο¡¼­ PDC(ÁÖ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯) ¿¡¹Ä·¹ÀÌÅÍ ÀÛ¾÷ ¸¶½ºÅÍ ¿ªÇÒÀ» ÇÏ´Â µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡ ÇÖÇȽº¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ¶ÇÇÑ ÇöÀç PDC ¿¡¹Ä·¹ÀÌÅÍ ÀÛ¾÷ ¸¶½ºÅÍ ¿ªÇÒÀ» ÇÏ´Â µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯°¡ »ç¿ëÇÒ ¼ö ¾ø°Ô µÇ¸é ÀÌ ¿ªÇÒÀ» ´ë½ÅÇϱâ À§ÇØ »ç¿ëÇÏ´Â ¸ðµç µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡µµ ÇÖÇȽº¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ¿ªÇÒÀ» ´ë½ÅÇϱâ À§ÇØ ¾î¶² µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¸¦ »ç¿ëÇÒÁö Àß ¸ð¸¦ °æ¿ì¿¡´Â ¸ðµç µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡ ÇÖÇȽº¸¦ ¼³Ä¡ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÇÖÇȽº°¡ ¾ø´Â µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯°¡ PDC ¿¡¹Ä·¹ÀÌÅÍ ÀÛ¾÷ ¸¶½ºÅÍ ¿ªÇÒÀ» ¸ÃÀ¸¸é »ç¿ëÀÚÀÇ »ç¿ë ±ÇÇÑÀÌ ´Ù½Ã ¼³Á¤µË´Ï´Ù.

Windows 2000 ÇÖÇȽº Á¤º¸

ÇöÀç Áö¿øµÇ´Â ÇÖÇȽº¸¦ Microsoft¿¡¼­ ±¸ÇÒ ¼ö ÀÖÁö¸¸ ÀÌ ¹®¼­¿¡¼­ ¼³¸íÇÏ´Â ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ °ÍÀÏ »ÓÀ̹ǷΠÀÌ·¯ÇÑ Æ¯Á¤ ¹®Á¦°¡ ¹ß»ýÇÏ´Â ½Ã½ºÅÛ¿¡¸¸ ÀÌ ÇÖÇȽº¸¦ Àû¿ëÇØ¾ß ÇÕ´Ï´Ù.

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é Microsoft °í°´±â¼úÁö¿øºÎ¿¡ ¹®ÀÇÇÏ¿© ÇÖÇȽº¸¦ ±¸ÇϽʽÿÀ. Microsoft °í°´±â¼úÁö¿øºÎ ÀüÈ­ ¹øÈ£ÀÇ Àüü ¸ñ·Ï°ú Áö¿ø ºñ¿ë¿¡ ´ëÇÑ Á¤º¸¸¦ º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
±â¼úÁö¿ø ¼­ºñ½º ¾È³»
Âü°í?ƯÁ¤ ¾÷µ¥ÀÌÆ®·Î ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ÀÖ´Ù°í Microsoft ±â¼úÁö¿ø Àü¹®°¡°¡ ÆÇ´ÜÇÒ °æ¿ì Áö¿ø ¿äû¿¡ µû¸¥ ÀϹÝÀû ºñ¿ëÀÌ Ãë¼ÒµÉ ¼öµµ ÀÖ½À´Ï´Ù. ÇØ´ç ¾÷µ¥ÀÌÆ®·Î ÇØ°áÇÒ ¼ö ¾ø´Â Ãß°¡ Áú¹®°ú ¹®Á¦¿¡ ´ëÇØ¼­´Â Áö¿ø ºñ¿ëÀÌ Ã»±¸µË´Ï´Ù.

´Ù½Ã ½ÃÀÛ ¿ä±¸ »çÇ×

ÀÌ ÇÖÇȽº¸¦ Àû¿ëÇÑ ÈÄ¿¡´Â ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

ÇÖÇȽº ´ëü Á¤º¸

ÀÌ ÇÖÇȽº´Â ´Ù¸¥ ÇÖÇȽº¸¦ ´ëüÇÏÁö ¾Ê½À´Ï´Ù.

ÆÄÀÏ Á¤º¸

ÀÌ ÇÖÇȽºÀÇ ¿µ¾î ¹öÀüÀº ¾Æ·¡¿Í °°°Å³ª ±× ÀÌ»óÀÇ ÆÄÀÏ Æ¯¼ºÀ» °®½À´Ï´Ù. ÀÌ ÆÄÀÏÀÇ ³¯Â¥¿Í ½Ã°£Àº UTC(Coordinated Universal Time)·Î ³ª¿­µÇ¸ç ÆÄÀÏ Á¤º¸¸¦ º¼ ¶§ ·ÎÄà ½Ã°£À¸·Î º¯È¯µË´Ï´Ù. UTC¿Í ·ÎÄà ½Ã°£ÀÇ Â÷À̸¦ º¸·Á¸é Á¦¾îÆÇÀÇ ³¯Â¥ ¹× ½Ã°£ Ç׸ñ¿¡¼­ Ç¥ÁØ ½Ã°£´ë ÅÇÀ» »ç¿ëÇϽʽÿÀ.
Ç¥ Ãà¼ÒÇ¥ È®´ë
³¯Â¥½Ã°£¹öÀüÅ©±âÆÄÀÏ À̸§
2004-03-2402:175.0.2195.6876388,368Advapi32.dll
2004-03-2402:175.0.2195.686669,904Browser.dll
2004-03-2402:175.0.2195.6824134,928Dnsapi.dll
2004-03-2402:175.0.2195.687692,432Dnsrslvr.dll
2004-03-2402:175.0.2195.688347,888Eventlog.dll
2004-03-2402:175.0.2195.6890143,632Kdcsvc.dll
2004-03-1102:375.0.2195.6903210,192Kerberos.dll
2003-09-2100:325.0.2195.682471,888Ksecdd.sys
2004-03-1102:375.0.2195.6902520,976Lsasrv.dll
2004-02-2523:595.0.2195.690233,552Lsass.exe
2003-06-1920:055.0.2195.6680117,520Msv1_0.dll
2004-03-2402:175.0.2195.6897312,592Netapi32.dll
2003-06-1920:055.0.2195.6695371,984Netlogon.dll
2004-08-1000:175.0.2195.6966933,648Ntdsa.dll
2004-03-2402:175.0.2195.6897388,368Samsrv.dll
2004-03-2402:175.0.2195.6893111,376Scecli.dll
2004-03-2402:175.0.2195.6903253,200Scesrv.dll
2004-06-0423:135.0.2195.69355,887,488Sp3res.dll
2004-03-2402:175.0.2195.682450,960W32time.dll
2003-09-2100:325.0.2195.682457,104W32tm.exe

Windows Server 2003 ¼­ºñ½º ÆÑ Á¤º¸

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é Windows Server 2003¿ë Ãֽм­ºñ½º ÆÑÀ» ±¸ÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
889100 Windows Server 2003¿ë Ãֽм­ºñ½º ÆÑÀ» ±¸ÇÏ´Â ¹æ¹ý

Windows Server 2003 ÇÖÇȽº Á¤º¸

ÇöÀç Áö¿øµÇ´Â ÇÖÇȽº¸¦ Microsoft¿¡¼­ ±¸ÇÒ ¼ö ÀÖÁö¸¸ ÀÌ ¹®¼­¿¡¼­ ¼³¸íÇÏ´Â ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ °ÍÀÏ »ÓÀ̹ǷΠÀÌ·¯ÇÑ Æ¯Á¤ ¹®Á¦°¡ ¹ß»ýÇÏ´Â ½Ã½ºÅÛ¿¡¸¸ ÀÌ ÇÖÇȽº¸¦ Àû¿ëÇϽʽÿÀ. ÀÌ ÇÖÇȽº´Â ³ªÁß¿¡ Ãß°¡ Å×½ºÆ®¸¦ ¹Þ¾Æ¾ß ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. µû¶ó¼­ ÀÌ ¹®Á¦ÀÇ ¿µÇâÀÌ ½É°¢ÇÏÁö ¾ÊÀ¸¸é ÀÌ ÇÖÇȽº°¡ Æ÷ÇÔµÈ ´ÙÀ½ Windows Server 2003 ¼­ºñ½º ÆÑÀÌ ³ª¿Ã ¶§±îÁö ±â´Ù¸®´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é Microsoft ¿Â¶óÀÎ °í°´ ¼­ºñ½º¿¡ ¿äûÀ» Á¦ÃâÇÏ¿© ÇÖÇȽº¸¦ ±¸ÇϽʽÿÀ. ÇÖÇȽº¸¦ ±¸Çϱâ À§ÇÑ ¿Â¶óÀÎ ¿äûÀ» Á¦ÃâÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://go.microsoft.com/?linkid=6294451
Âü°í ¹®Á¦°¡ Ãß°¡·Î ¹ß»ýÇϰųª ¹®Á¦ ÇØ°áÀÌ ÇÊ¿äÇÑ °æ¿ì º°µµÀÇ ¼­ºñ½º ¿äûÀ» ÇØ¾ß ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ Æ¯Á¤ ÇÖÇȽº·Î ÇØ°áÇÒ ¼ö ¾ø´Â Ãß°¡ Áú¹®°ú ¹®Á¦¿¡ ´ëÇØ¼­´Â Áö¿ø ºñ¿ëÀÌ Ã»±¸µË´Ï´Ù. º°µµÀÇ ¼­ºñ½º ¿äûÀ» ÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
±â¼úÁö¿ø ¼­ºñ½º ¾È³»
ÀÌ ÇÖÇȽºÀÇ ¿µ¾î ¹öÀüÀº ¾Æ·¡¿Í °°°Å³ª ±× ÀÌ»óÀÇ ÆÄÀÏ Æ¯¼ºÀ» °®½À´Ï´Ù. ÀÌ ÆÄÀÏÀÇ ³¯Â¥¿Í ½Ã°£Àº UTC(Coordinated Universal Time)·Î ³ª¿­µÇ¸ç ÆÄÀÏ Á¤º¸¸¦ º¼ ¶§ ·ÎÄà ½Ã°£À¸·Î º¯È¯µË´Ï´Ù. UTC¿Í ·ÎÄà ½Ã°£ÀÇ Â÷À̸¦ º¸·Á¸é Á¦¾îÆÇÀÇ ³¯Â¥ ¹× ½Ã°£ Ç׸ñ¿¡¼­ Ç¥ÁØ ½Ã°£´ë ÅÇÀ» »ç¿ëÇϽʽÿÀ.

´Ù½Ã ½ÃÀÛ ¿ä±¸ »çÇ×

ÀÌ ÇÖÇȽº¸¦ Àû¿ëÇÑ ÈÄ¿¡´Â ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

ÇÖÇȽº ´ëü Á¤º¸

ÀÌ ÇÖÇȽº´Â ´Ù¸¥ ÇÖÇȽº¸¦ ´ëüÇÏÁö ¾Ê½À´Ï´Ù.

ÆÄÀÏ Á¤º¸

Windows Server 2003 32-Bit Edition
Ç¥ Ãà¼ÒÇ¥ È®´ë
³¯Â¥½Ã°£¹öÀüÅ©±âÆÄÀÏ À̸§
2004-11-0201:265.2.3790.2291,532,416Ntdsa.dll
2004-11-0201:265.2.3790.21232,768Ntdsatq.dll
2004-09-1911:415.2.3790.21259,392Ws03res.dll
Windows Server 2003 64-Bit Edition
Ç¥ Ãà¼ÒÇ¥ È®´ë
³¯Â¥½Ã°£¹öÀüÅ©±âÆÄÀÏ À̸§Ç÷§Æû
2004-11-0201:215.2.3790.2294,057,088Ntdsa.dllIA-64
2004-11-0201:215.2.3790.21282,432Ntdsatq.dllIA-64
2004-09-1909:435.2.3790.21258,880Ws03res.dllIA-64
2004-09-1911:415.2.3790.21259,392Wws03res.dllx86
Windows 2000°ú Windows Server 2003¿¡¼­ ÇÖÇȽº¸¦ ¼³Ä¡ÇÑ ÈÄ adminSDHolder·Î º¸È£µÇ´Â ¿î¿µÀÚ ±×·ìÀ» Á¦¾îÇϱâ À§ÇØ Æ÷¸®½ºÆ® Àüü¿¡ Àû¿ëµÇ´Â dsHeuristic Ç÷¡±×¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ¿Í °°Àº »õ ¿É¼ÇÀ» »ç¿ëÇÏ¸é ¸ñ·Ï¿¡ ³ª¿Í ÀÖ´Â ³× °³ÀÇ º¸È£µÇ´Â ±×·ì Áß ÀϺΠ¶Ç´Â ÀüºÎ¸¦ ¿ø·¡ Windows 2000 µ¿ÀÛÀ¸·Î µÇµ¹¸± ¼ö ÀÖ½À´Ï´Ù. ¹®ÀÚ À§Ä¡ 16Àº 16Áø¼ö °ªÀ¸·Î ÇØ¼®µÇ¸ç °¡Àå ¿ÞÂÊÀÇ ¹®ÀÚ°¡ À§Ä¡ 1ÀÔ´Ï´Ù. µû¶ó¼­ À¯È¿ÇÑ °ªÀº "0"¿¡¼­ "f"±îÁöÀÔ´Ï´Ù. °¢ ¿î¿µÀÚ ±×·ìÀº ´ÙÀ½°ú °°Àº ƯÁ¤ ºñÆ®·Î ³ªÅ¸³À´Ï´Ù.
  • ºñÆ® 0: Account Operators
  • ºñÆ® 1: Server Operators
  • ºñÆ® 2: Print Operators
  • ºñÆ® 3: Backup Operators
¿¹¸¦ µé¾î, °ª 0001Àº Account Operators Á¦¿Ü¸¦ ÀǹÌÇÕ´Ï´Ù. ÀÌÁø¼ö ÇÕ°è 1100ÀÌ 16Áø¼ö °ª 0xC¸¦ ³ªÅ¸³»¹Ç·Î °ª 'c'´Â Print Operators(0100) ¹× Backup Operators(1000)¸¦ Á¦¿ÜÇÕ´Ï´Ù.

»õ ±â´ÉÀ» »ç¿ëÇÏ·Á¸é ±¸¼º ÄÁÅ×À̳ʿ¡¼­ °³Ã¼¸¦ ¼öÁ¤ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ¼³Á¤Àº Æ÷¸®½ºÆ® Àüü¿¡ Àû¿ëµË´Ï´Ù. °³Ã¼¸¦ ¼öÁ¤ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ¼öÁ¤ÇÒ °³Ã¼¸¦ ã½À´Ï´Ù. ÀÌ ÀÛ¾÷À» ¼öÇàÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
    326690 Windows Server 2003 µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¼­ Active Directory¿¡ ´ëÇØ À͸í LDAP ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ¾ø´Ù
  2. ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ ldp.exe¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´­·¯ LDP À¯Æ¿¸®Æ¼¸¦ ½ÃÀÛÇÕ´Ï´Ù.
  3. ConnectionÀ» ´©¸£°í connect¸¦ ´©¸¥ ´ÙÀ½ OK¸¦ ´©¸¨´Ï´Ù.
  4. ConnectionÀ» ´©¸£°í Bind¸¦ ´©¸¥ ´ÙÀ½ Æ÷¸®½ºÆ® ·çÆ® °ü¸®ÀÚÀÇ »ç¿ëÀÚ À̸§°ú ¾ÏÈ£¸¦ ÀÔ·ÂÇϰí OK¸¦ ´©¸¨´Ï´Ù.
  5. View¸¦ ´©¸£°í Tree¸¦ ´©¸¥ ´ÙÀ½ OK¸¦ ´©¸¨´Ï´Ù.
  6. View\Tree¸¦ »ç¿ëÇÏ¿© ´ÙÀ½°ú °°Àº ±¸¼º CNÀ» ¿±´Ï´Ù.
    CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=Forest root domain
  7. Directory Service °³Ã¼¸¦ ã¾Æ µÎ ¹ø ´©¸¨´Ï´Ù.
  8. ¿À¸¥ÂÊÀÇ °³Ã¼ Ư¼º ¸ñ·ÏÀ» °ËÅäÇÏ¿© dsHeuristics Ư¼ºÀÌ ÀÌ¹Ì ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ¼³Á¤µÇ¾î ÀÖÀ¸¸é ±âÁ¸ °ªÀ» Ŭ¸³º¸µå¿¡ º¹»çÇÕ´Ï´Ù.
  9. ¿ÞÂÊÀÇ Directory Service °³Ã¼¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸£°í ¼öÁ¤À» ´©¸¨´Ï´Ù.
  10. Ư¼º À̸§À¸·Î dsHeuristics¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  11. °ªÀ¸·Î 000000000100000f¸¦ ÀÔ·ÂÇÕ´Ï´Ù. dsHeuristics¿¡ ÀÌ¹Ì °ªÀÌ ÀÖÀ¸¸é ÀÌ °ªÀ¸·Î À§¿¡ ÀÖ´Â °ªÀÇ Ã³À½ ºÎºÐ¿¡ ÀÖ´Â 0À» ´ëüÇÕ´Ï´Ù. "f" ¶Ç´Â ¼³Á¤ÇÒ ºñÆ®±îÁöÀÇ ÀÚ¸´¼ö°¡ ¿Ã¹Ù¸¥Áö È®ÀÎÇÕ´Ï´Ù.

    Âü°í ¿Ã¹Ù¸¥ ¹®ÀÚ¸¦ ¼öÁ¤Çϰí ÀÖ´ÂÁö È®ÀÎÇϱâ À§ÇØ ¸ðµç 10¹øÂ° ¹®ÀÚ°¡ ±× ÁöÁ¡±îÁöÀÇ ¹®ÀÚ ¼ö¸¦ 10À¸·Î ³ª´« ¼ö·Î ¼³Á¤µÇ¾î¾ß ÇÕ´Ï´Ù. ¿¹¸¦ µé¾î, 10¹øÂ° ¹®ÀÚ´Â 1, 20¹øÂ° ¹®ÀÚ´Â 2, 30¹øÂ° ¹®ÀÚ´Â 3 µîÀ¸·Î ¼³Á¤µÇ¾î¾ß ÇÕ´Ï´Ù.
  12. Ư¼ºÀÌ ÀÌ¹Ì ÀÖÀ¸¸é Operation »óÀÚ¿¡¼­ Replace¸¦ ´©¸£°í Ư¼ºÀÌ ¾øÀ¸¸é Add¸¦ ´©¸¨´Ï´Ù.
  13. Operation ±×·ìÀÇ ¿À¸¥ÂÊ¿¡¼­ Enter ۸¦ ´­·¯ ÀÌ ±×·ìÀ» LDAP Æ®·£Àè¼Ç¿¡ Ãß°¡ÇÕ´Ï´Ù.
  14. RunÀ» ´­·¯ °³Ã¼¿¡ º¯°æ »çÇ×À» Àû¿ëÇÕ´Ï´Ù. ÀÌ º¯°æ »çÇ×ÀÌ Æ÷¸®½ºÆ®ÀÇ PDC ¿¡¹Ä·¹ÀÌÅÍ¿¡ º¹Á¦µÇ°í ³ª¸é ÀÌ ÇÖÇȽº¸¦ ½ÇÇàÇÏ´Â PDC ¿¡¹Ä·¹ÀÌÅÍ´Â ºñÆ®°¡ ¼³Á¤µÈ ¿î¿µÀÚ ±×·ìÀÇ ±¸¼º¿øÀÎ »ç¿ëÀÚ¸¦ º¸È£ÇÏÁö ¾Ê½À´Ï´Ù.

ÇØ°á °úÁ¤

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é ´ÙÀ½ ¹æ¹ý Áß Çϳª¸¦ ¼öÇàÇϽʽÿÀ.

¹æ¹ý 1: ±¸¼º¿øÀÌ º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÌ ¾Æ´ÑÁö È®ÀÎ

Á¶Á÷ ±¸¼º ´ÜÀ§ ¼öÁØ¿¡¼­ À§ÀӵǴ »ç¿ë ±ÇÇÑÀ» »ç¿ëÇÏ´Â °æ¿ì À§ÀÓµÈ »ç¿ë ±ÇÇÑÀÌ ÇÊ¿äÇÑ ¸ðµç »ç¿ëÀÚ°¡ º¸È£µÇ´Â ±×·ì Áß ÇϳªÀÇ ±¸¼º¿øÀÌ ¾Æ´ÑÁö È®ÀÎÇØ¾ß ÇÕ´Ï´Ù. ÀÌÀü¿¡ º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀ̾ú´ø »ç¿ëÀÚ´Â º¸È£µÇ´Â ±×·ì¿¡¼­ Á¦°ÅµÉ ¶§ »ó¼Ó Ç÷¡±×°¡ ÀÚµ¿À¸·Î ´Ù½Ã ¼³Á¤µÇÁö ¾Ê½À´Ï´Ù. º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÌ ¾Æ´ÑÁö È®ÀÎÇÏ·Á¸é ¾Æ·¡ÀÇ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇϽʽÿÀ.

Âü°í ÀÌ ½ºÅ©¸³Æ®´Â AdminCount°¡ 1·Î ¼³Á¤µÈ ¸ðµç »ç¿ëÀÚÀÇ »ó¼Ó Ç÷¡±×¸¦ °Ë»çÇÕ´Ï´Ù. »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ¾ø´Â °æ¿ì(SE_DACL_PROTECTED°¡ ¼³Á¤µÇ¾î ÀÖ´Â °æ¿ì) ÀÌ ½ºÅ©¸³Æ®´Â »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÕ´Ï´Ù. »ó¼ÓÀÌ ÀÌ¹Ì »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤µÇ¾î ÀÖ´Â °æ¿ì¿¡´Â ¼³Á¤ÀÌ À¯ÁöµË´Ï´Ù. ¶ÇÇÑ AdminCount°¡ 0À¸·Î ´Ù½Ã ¼³Á¤µË´Ï´Ù. adminSDHolder ½º·¹µå°¡ ´Ù½Ã ½ÇÇàµÇ¸é »ó¼ÓÀÌ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤µÇ°í º¸È£µÇ´Â ±×·ì¿¡ ³²¾Æ ÀÖ´Â ¸ðµç »ç¿ëÀÚÀÇ AdminCount°¡ 1·Î ¼³Á¤µË´Ï´Ù. µû¶ó¼­ ´õ ÀÌ»ó º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÌ ¾Æ´Ñ ¸ðµç »ç¿ëÀÚÀÇ AdminCount ¹× »ó¼ÓÀÌ ¿Ã¹Ù·Î ¼³Á¤µË´Ï´Ù.

ÀÌ ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ·Á¸é ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇϽʽÿÀ.
cscript /nologo resetaccountsadminsdholder.vbs
Microsoft´Â ¸ðµç º¸Áõ(»óǰ, ƯÁ¤ ¸ñÀû¿¡ ´ëÇÑ ÀûÇÕ¼º ¹× ºñÄ§ÇØ¿¡ ´ëÇÑ ¹¬½ÃÀûÀÎ º¸ÁõÀ» Æ÷ÇÔÇϸç ÀÌ¿¡ Á¦ÇѵÇÁö ¾ÊÀ½)À» ¹èÁ¦ÇÏ¸ç ¿¹¸¦ º¸¿©ÁÖ±â À§ÇÑ ¸ñÀûÀ¸·Î¸¸ ÀÌ ÇÁ·Î±×·¡¹Ö ¿¹Á¦¸¦ Á¦°øÇÕ´Ï´Ù. º» ¹®¼­ÀÇ ³»¿ëÀº ÇÁ·Î½ÃÀú¸¦ ÀÛ¼ºÇÏ°í µð¹ö±ëÇÏ´Â µ¥ »ç¿ëµÇ´Â µµ±¸ ¹× ¿©±â¼­ ¼³¸íÇÏ´Â ÇÁ·Î±×·¡¹Ö ¾ð¾î¿¡ Àͼ÷ÇÑ »ç¿ëÀÚ¸¦ ´ë»óÀ¸·Î ÇÕ´Ï´Ù. Microsoft Áö¿ø ¿£Áö´Ï¾î´Â »ç¿ëÀÚ¿¡°Ô µµ¿òÀÌ µÇµµ·Ï ƯÁ¤ ÇÁ·Î½ÃÀú¿¡ ´ëÇÑ ±â´ÉÀ» ¼³¸íÇÒ ¼ö ÀÖÁö¸¸ »ç¿ëÀÚÀÇ Æ¯Á¤ ¿ä±¸ »çÇ׿¡ ¸Âµµ·Ï ¿¹Á¦¸¦ ¼öÁ¤ÇÏ¿© Ãß°¡ ±â´ÉÀ» Á¦°øÇϰųª ÇÁ·Î½ÃÀú¸¦ ±¸¼ºÇÏÁö´Â ¾Ê½À´Ï´Ù.
'********************************************************************
'*
'* File:           ResetAccountsadminSDHolder.vbs 
'* Created:        November 2003
'* Version:        1.0
'*
'*  Main Function:  Resets all accounts that have adminCount = 1 back
'*	to 0 and enables the inheritance flag
'*
'*  ResetAccountsadminSDHolder.vbs 
'*
'* Copyright (C) 2003 Microsoft Corporation
'*
'********************************************************************

Const SE_DACL_PROTECTED = 4096

On Error Resume Next

Dim sDomain
Dim sADsPath
Dim sPDC


Dim oCon 
Dim oCmd
Dim oRst
Set oRst = CreateObject("ADODB.Recordset")
Set oCmd = CreateObject("ADODB.Command")
Set oCon = CreateObject("ADODB.Connection")

Dim oRoot
Dim oDomain
Dim oADInfo
Dim oInfo
Set oADInfo = CreateObject("ADSystemInfo")
Set oInfo = CreateObject("WinNTSystemInfo")
sPDC = oInfo.PDC & "." & oADInfo.DomainDNSName

oCon.Provider = "ADSDSOObject"
oCon.Open "Active Directory Provider"

oCmd.ActiveConnection = oCon

Set oRoot = GetObject("LDAP://rootDSE")
sDomain = oRoot.Get("defaultNamingContext")
Set oDomain = GetObject("LDAP://" & sDomain)
sADsPath = "<" & oDomain.ADsPath & ">"

oCmd.CommandText = "SELECT ADsPath FROM 'LDAP://" & sPDC & "/" & sDomain & "' WHERE objectCategory='person' and objectClass = 'user' AND adminCount = 1"
Set oRst = oCmd.Execute

WScript.Echo "searching for objects with 'admin count = 1' in " & sDomain

If oRst.RecordCount = 0 Then
    WScript.Echo "no accounts found"
    WScript.Quit
End If 

Do While Not oRst.EOF
    WScript.Echo  "found object " & oRst.Fields("ADsPath")
    If SetInheritanceFlag(oRst.Fields("ADsPath")) = 0 Then WScript.Echo "Inheritance flag set"
    If SetAdminCount(oRst.Fields("ADsPath"), 0) = 0 Then WScript.Echo "adminCount set to 0"
    WScript.Echo  "=========================================="
    oRst.MoveNext
Loop


Private Function SetInheritanceFlag(DSObjectPath)

    Dim oSD
    Dim oDACL
    Dim lFlag
    Dim oIADs

    Set oIADs = GetObject(DSObjectPath)

    Set oSD = oIADs.Get("nTSecurityDescriptor")

    If oSD.Control And SE_DACL_PROTECTED Then
        oSD.Control = oSD.Control - SE_DACL_PROTECTED
    End If 

    oIADs.Put "nTSecurityDescriptor", oSD
    oIADs.SetInfo
    
    If Err.Number <> 0 Then
        SetInheritanceFlag = Err.Number
    Else
        SetInheritanceFlag = 0
    End If 

End Function


Private Function SetAdminCount(DSObjectPath, AdminCount)

    Dim oIADs
    Dim iAdminCount

    Set oIADs = GetObject(DSObjectPath)

    iAdminCount = oIADs.Get("adminCount")

    If iAdminCount = 1 Then iAdminCount = 0

    oIADs.Put "adminCount", iAdminCount
    oIADs.SetInfo
    If Err.Number <> 0 Then
        SetAdminCount = Err.Number
    Else
        SetAdminCount = 0
    End If 
    
End Function
»ç¿ëÀÚ¿¡°Ô ºÎÁ¤ÀûÀÎ ¿µÇâÀ» ¹ÌÄ¡Áö ¾ÊÀ¸·Á¸é Ldifde.exe¸¦ »ç¿ëÇÏ¿© AdminCount°¡ 1·Î ¼³Á¤µÈ »ç¿ëÀÚ¸¦ ¸ÕÀú ´ýÇÁÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸£½Ê½Ã¿À.
ldifde -f Admincount-1.txt -d dc=your domain -r "(&(objectcategory=person)(objectclass=user)(admincount=1))"
Ãâ·Â ÆÄÀÏÀ» °ËÅäÇÏ¿© DACL º¸È£ ºñÆ®°¡ ÇØÁ¦µÉ ¸ðµç »ç¿ëÀÚ°¡ »ó¼ÓµÈ ACE(Access Controlled Entry)¸¸ Æ÷ÇÔµÈ ÀûÀýÇÑ »ç¿ë ±ÇÇÑÀ» °®°Ô µÇ´ÂÁö È®ÀÎÇϽʽÿÀ. ÀÌ ¹æ¹ýÀº ÁÖ·Î »ç¿ëµÇ´Â ¹æ¹ýÀÌ¸ç ±âÁ¸ º¸¾ÈÀ» ¾àÈ­½ÃŰÁö ¾Ê½À´Ï´Ù.

¹æ¹ý 2: adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤

adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÏ¸é º¸È£µÇ´Â ±×·ìÀÇ ¸ðµç ±¸¼º¿øÀÌ »ó¼ÓµÈ »ç¿ë ±ÇÇÑÀ» »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹æ¹ýÀ» »ç¿ëÇÏ¸é º¸¾È ±â´É Ãø¸é¿¡¼­ adminSDHolder ÄÁÅ×À̳ÊÀÇ µ¿ÀÛÀÌ ¼­ºñ½º ÆÑ 4 ÀÌÀü ±â´ÉÀ¸·Î µÇµ¹¾Æ°©´Ï´Ù.

adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤

adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÏ¸é µÎ °¡Áö º¸È£ ACL(¾×¼¼½º Á¦¾î ¸ñ·Ï) ¸ÞÄ¿´ÏÁò Áß Çϳª¸¦ »ç¿ëÇÒ ¼ö ¾ø°Ô µÇ°í ±âº» »ç¿ë ±ÇÇÑÀÌ Àû¿ëµË´Ï´Ù. ±×·¯³ª Á¶Á÷ ±¸¼º ´ÜÀ§ ¼öÁØ¿¡¼­ »ó¼ÓÀÌ »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤µÇ¾î ÀÖÀ¸¸é º¸È£µÇ´Â ±×·ìÀÇ ¸ðµç ±¸¼º¿øÀÌ Á¶Á÷ ±¸¼º ´ÜÀ§¿Í ºÎ¸ð Á¶Á÷ ±¸¼º ´ÜÀ§¿¡¼­ »ç¿ë ±ÇÇÑÀ» »ó¼ÓÇÕ´Ï´Ù.

°ü¸®ÀÚ¿¡°Ô »ó¼Ó º¸È£ ±â´ÉÀ» Á¦°øÇÏ·Á¸é ¸ðµç °ü¸®ÀÚ¿Í »ó¼Ó º¸È£°¡ ÇÊ¿äÇÑ ´Ù¸¥ »ç¿ëÀÚ¸¦ ÇØ´ç Á¶Á÷ ±¸¼º ´ÜÀ§·Î ¿Å±é´Ï´Ù. Á¶Á÷ ±¸¼º ´ÜÀ§ ¼öÁØ¿¡¼­ »ó¼ÓÀ» Á¦°ÅÇÑ ´ÙÀ½ adminSDHolder ÄÁÅ×À̳ÊÀÇ ÇöÀç ACL°ú ÀÏÄ¡Çϵµ·Ï »ç¿ë ±ÇÇÑÀ» ¼³Á¤ÇÕ´Ï´Ù. adminSDHolder ÄÁÅ×À̳ÊÀÇ »ç¿ë ±ÇÇÑÀÌ ´Ù¾çÇÒ ¼ö Àֱ⠶§¹®¿¡(¿¹¸¦ µé¾î, Microsoft Exchange Server¿¡¼­ ÀϺΠ»ç¿ë ±ÇÇÑÀ» Ãß°¡Çϰųª »ç¿ë ±ÇÇÑÀÌ ¼öÁ¤µÇ¾úÀ» ¼ö ÀÖÀ½) º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀ» °ËÅäÇÏ¿© adminSDHolder ÄÁÅ×À̳ÊÀÇ ÇöÀç »ç¿ë ±ÇÇÑÀ» È®ÀÎÇØ¾ß ÇÕ´Ï´Ù. UI(»ç¿ëÀÚ ÀÎÅÍÆäÀ̽º)·Î´Â adminSDHolder ÄÁÅ×À̳ÊÀÇ ¸ðµç »ç¿ë ±ÇÇÑÀÌ Ç¥½ÃµÇÁö ¾Ê½À´Ï´Ù. adminSDHolder ÄÁÅ×À̳ÊÀÇ ¸ðµç »ç¿ë ±ÇÇÑÀ» º¸·Á¸é DSacls¸¦ »ç¿ëÇϽʽÿÀ.

ADSI ÆíÁýÀ̳ª Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»Å͸¦ »ç¿ëÇÏ¿© adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. adminSDHolder ÄÁÅ×À̳ÊÀÇ °æ·Î´Â CN=adminSDHolder,CN=System,DC=<MyDomain>,DC=<Com>ÀÔ´Ï´Ù.

Âü°í Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»Å͸¦ »ç¿ëÇÏ´Â °æ¿ì º¸±â ¸Þ´º¿¡¼­ °í±Þ ±â´ÉÀ» ¼±ÅÃÇØ¾ß ÇÕ´Ï´Ù.

adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ÄÁÅ×À̳ʸ¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ´ÙÀ½ ¼Ó¼ºÀ» ´©¸¨´Ï´Ù.
  2. º¸¾È ÅÇÀ» ´©¸¨´Ï´Ù.
  3. °í±ÞÀ» ´©¸¨´Ï´Ù.
  4. »ó¼Ó °¡´ÉÇÑ ±ÇÇÑÀ» ºÎ¸ð °³Ã¼¿¡¼­ ÀÌ °³Ã¼ ¹× ¸ðµç ÀÚ½Ä °³Ã¼¿¡ ÀüÆÄÇÒ ¼ö ÀÖÀ½ È®ÀζõÀ» ¼±ÅÃÇÕ´Ï´Ù.
  5. È®ÀÎÀ» ´©¸¥ ´ÙÀ½ ´Ý±â¸¦ ´©¸¨´Ï´Ù.
´ÙÀ½¿¡ SDProp ½º·¹µå°¡ ½ÇÇàµÉ ¶§ »ó¼Ó Ç÷¡±×°¡ º¸È£µÇ´Â ±×·ìÀÇ ¸ðµç ±¸¼º¿ø¿¡ ´ëÇØ ¼³Á¤µË´Ï´Ù. ÀÌ ÀýÂ÷´Â 60ºÐ±îÁö °É¸± ¼ö ÀÖ½À´Ï´Ù. ÀÌ º¯°æ »çÇ×ÀÌ PDC(ÁÖ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯)¿¡¼­ º¹Á¦µÉ ¶§±îÁö ±â´Ù·Á¾ß ÇÕ´Ï´Ù.

¹æ¹ý 3: »ó¼ÓÀ» ¹æÁöÇϰí ACL¸¸ º¯°æ

º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÎ »ç¿ëÀÚ°¡ ÇØ´ç »ç¿ëÀÚ°¡ ¼ÓÇØ ÀÖ´Â ÄÁÅ×À̳ʿ¡¼­ »ç¿ë ±ÇÇÑÀ» »ó¼ÓÇÏÁö ¸øÇÏ°Ô ÇÏ°í »ç¿ëÀÚ °³Ã¼¿¡ ´ëÇÑ º¸¾È¸¸ º¯°æÇÏ·Á¸é adminSDHolder ÄÁÅ×ÀÌ³Ê µð·ºÅ͸®¿¡ ´ëÇÑ º¸¾ÈÀ» ÆíÁýÇÏ¸é µË´Ï´Ù. ÀÌ °æ¿ì adminSDHolder ÄÁÅ×À̳ʿ¡¼­ »ó¼ÓÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ¼³Á¤ÇÒ Çʿ䰡 ¾øÀ¸¸ç, ÇØ´ç ±×·ìÀ» Ãß°¡Çϰųª adminSDHolder ÄÁÅ×À̳ʿ¡ ´ëÇØ ÀÌ¹Ì Á¤ÀǵǾî ÀÖ´Â º¸¾È ±×·ìÀÇ º¸¾ÈÀ» ÆíÁýÇϱ⸸ ÇÏ¸é µË´Ï´Ù. 1½Ã°£ ÈÄ¿¡ SDProp ½º·¹µå°¡ adminSDHolder ÄÁÅ×À̳ÊÀÇ ACL¿¡ ´ëÇÑ º¯°æ »çÇ×À» º¸È£µÇ´Â ±×·ìÀÇ ¸ðµç ±¸¼º¿ø¿¡ Àû¿ëÇÕ´Ï´Ù. ±¸¼º¿øÀº ÀÚ½ÅÀÌ ¼ÓÇØ ÀÖ´Â ÄÁÅ×À̳ÊÀÇ º¸¾ÈÀ» »ó¼ÓÇÏÁö ¾Ê½À´Ï´Ù.

¿¹¸¦ µé¾î, Self °èÁ¤¿¡´Â Allow to Read All Properties ±ÇÇÑÀÌ ÇÊ¿äÇÕ´Ï´Ù. Self °èÁ¤¿¡ ÀÌ ±ÇÇÑÀ» Çã¿ëÇϵµ·Ï adminSDHolder ÄÁÅ×ÀÌ³Ê º¸¾È ¼³Á¤À» ÆíÁýÇÕ´Ï´Ù. 1½Ã°£ ÈÄ¿¡ ÀÌ ±ÇÇÑÀº º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÎ ¸ðµç »ç¿ëÀÚÀÇ Self °èÁ¤¿¡ Çã¿ëµË´Ï´Ù. »ó¼Ó Ç÷¡±×´Â º¯°æµÇÁö ¾Ê½À´Ï´Ù.

´ÙÀ½ ¿¹Á¦¿¡¼­´Â adminSDHolder °³Ã¼¿¡¸¸ º¯°æ »çÇ×À» Àû¿ëÇÏ´Â ¹æ¹ýÀ» º¸¿© ÁÝ´Ï´Ù. ÀÌ ¿¹Á¦¿¡¼­´Â adminSDHolder °³Ã¼¿¡ ´ÙÀ½°ú °°Àº ±ÇÇÑÀ» ºÎ¿©ÇÕ´Ï´Ù.
  • ³»¿ë º¸±â
  • ¸ðµç ¼Ó¼º Àбâ
  • ¸ðµç ¼Ó¼º ¾²±â
adminSDHolder °³Ã¼¿¡ ÀÌ·¯ÇÑ ±ÇÇÑÀ» ºÎ¿©ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»ÅÍÀÇ º¸±â ¸Þ´º¿¡¼­ °í±Þ ±â´ÉÀ» ´©¸¨´Ï´Ù.
  2. adminSDHolder °³Ã¼¸¦ ã½À´Ï´Ù. °³Ã¼´Â Active Directory Æ÷¸®½ºÆ®ÀÇ °¢ µµ¸ÞÀο¡ ´ëÇØ CN=adminSDHolder,CN=System,DC=domain,DC=com¿¡ ÀÖ½À´Ï´Ù. ¿©±â¼­ DC=domain,DC=comÀº µµ¸ÞÀÎÀÇ DN(°íÀ¯ À̸§)ÀÔ´Ï´Ù.
  3. adminSDHolder¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ´ÙÀ½ ¼Ó¼ºÀ» ´©¸¨´Ï´Ù.
  4. ¼Ó¼º ´ëÈ­ »óÀÚ¿¡¼­ º¸¾È ÅÇÀ» ´©¸¥ ´ÙÀ½ °í±ÞÀ» ´©¸¨´Ï´Ù.
  5. Access Control Settings for adminSDHolder ´ëÈ­ »óÀÚÀÇ »ç¿ë ±ÇÇÑ ÅÇ¿¡¼­ Ãß°¡¸¦ ´©¸¨´Ï´Ù.
  6. Select User, Computer, or Group ´ëÈ­ »óÀÚ¿¡¼­ °ü·Ã ±ÇÇÑÀ» ºÎ¿©ÇÒ °èÁ¤À» ´©¸¥ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
  7. adminSDHolder ±ÇÇÑ Ç׸ñ ´ëÈ­ »óÀÚÀÇ Àû¿ë ´ë»ó »óÀÚ¿¡¼­ ÀÌ °³Ã¼¸¸À» ´©¸¥ ´ÙÀ½ ³»¿ë º¸±â, ¸ðµç ¼Ó¼º ÀÐ±â ¹× ¸ðµç ¼Ó¼º ¾²±â ±ÇÇÑÀ» ´©¸¨´Ï´Ù.
  8. È®ÀÎÀ» ´­·¯ adminSDHolder ±ÇÇÑ Ç׸ñ ´ëÈ­ »óÀÚ, adminSDHolder¿¡ ´ëÇÑ ¾×¼¼½º ÄÁÆ®·Ñ ¼³Á¤ ´ëÈ­ »óÀÚ ¹× adminSDHolder ¼Ó¼º ´ëÈ­ »óÀÚ¸¦ ´Ý½À´Ï´Ù.
1½Ã°£ ¾È¿¡ º¸È£µÇ´Â ±×·ì°ú °ü·ÃµÈ »ç¿ëÀÚ °³Ã¼¿¡ ´ëÇÑ ACLÀÌ ¾÷µ¥ÀÌÆ®µÇ¾î º¯°æ »çÇ×ÀÌ ¹Ý¿µµË´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
232199 Active Directory adminSDHolder °³Ã¼¿¡ ´ëÇÑ ¼³¸í ¹× ¾÷µ¥ÀÌÆ®
318180 AdminSDHolder ½º·¹µå°¡ ¸ÞÀÏ ±×·ìÀÇ ÀüÀÌ ±¸¼º¿ø¿¡ ¿µÇâÀ» ¹ÌÄ£´Ù

ÇöÀç »óÅÂ

Microsoft´Â "º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù." Àý¿¡ ³ª¿­ÇÑ Á¦Ç°¿¡¼­ ÀÌ ¹®Á¦¸¦ È®ÀÎÇß½À´Ï´Ù. ÀÌ ¹®Á¦´Â Windows Server 2003 ¼­ºñ½º ÆÑ 1¿¡¼­ óÀ½ ÇØ°áµÇ¾ú½À´Ï´Ù.

Ãß°¡ Á¤º¸

Active Directory¿¡¼­´Â Áß¿äÇÑ ±×·ìÀÇ ±¸¼º¿ø¿¡ ´ëÇØ ACLÀÌ ¿Ã¹Ù¸£°Ô ¼³Á¤µÇµµ·Ï Çϱâ À§ÇØ º¸È£ ¸ÞÄ¿´ÏÁòÀ» »ç¿ëÇÕ´Ï´Ù. ÀÌ ¸ÞÄ¿´ÏÁòÀº PDC ÀÛ¾÷ ¸¶½ºÅÍ¿¡¼­ ÇÑ ½Ã°£¿¡ ÇÑ ¹ø¾¿ ½ÇÇàµË´Ï´Ù. ÀÛ¾÷ ¸¶½ºÅÍ´Â º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÎ »ç¿ëÀÚ °èÁ¤¿¡ ´ëÇÑ ACLÀ» ´ÙÀ½ °³Ã¼¿¡ ´ëÇÑ ACL°ú ºñ±³ÇÕ´Ï´Ù.
CN=adminSDHolder,CN=System,DC=<MyDomain>,DC=<Com>

Âü°í "DC=<MyDomain>,DC=<Com>"Àº µµ¸ÞÀÎÀÇ DN(°íÀ¯ À̸§)À» ³ªÅ¸³À´Ï´Ù.

ACLÀÌ ´Ù¸£¸é »ç¿ëÀÚ °³Ã¼¿¡ ´ëÇÑ ACLÀÌ adminSDHolder °³Ã¼ÀÇ º¸¾È ¼³Á¤À» ¹Ý¿µÇϱâ À§ÇØ µ¤¾î¾²À̰í ACL »ó¼ÓÀÌ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤µË´Ï´Ù. ÀÌ·¯ÇÑ °úÁ¤ÀÌ Àֱ⠶§¹®¿¡ º¸È£µÇ´Â ±×·ìÀÇ ±¸¼º¿øÀÎ »ç¿ëÀÚ °èÁ¤ÀÌ ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ¿¡°Ô »ç¿ëÀÚ °èÁ¤À» ¼öÁ¤ÇÒ °ü¸® ÀÚ°Ý Áõ¸íÀÌ À§ÀÓµÈ ÄÁÅ×À̳ʳª Á¶Á÷ ±¸¼º ´ÜÀ§·Î ¿Å°ÜÁø °æ¿ì ±ÇÇÑÀÌ ¾ø´Â »ç¿ëÀÚ°¡ ÇØ´ç °èÁ¤À» ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù. »ç¿ëÀÚ°¡ °ü¸® ±×·ì¿¡¼­ Á¦°ÅµÇ´Â °æ¿ì¿¡´Â ÀÌ·¯ÇÑ °úÁ¤ÀÌ ¹Ý´ë·Î ¼öÇàµÇÁö ¾ÊÀ¸¹Ç·Î ¼öµ¿À¸·Î º¯°æÇØ¾ß ÇÕ´Ï´Ù.

Âü°í adminSDHolder °³Ã¼°¡ º¸¾È ¼³¸íÀÚ¸¦ ¾÷µ¥ÀÌÆ®ÇÏ´Â ºóµµ¸¦ Á¦¾îÇÏ·Á¸é ¾Æ·¡ÀÇ ·¹Áö½ºÆ®¸® ÇÏÀ§ Ű¿¡¼­ AdminSDProtectFrequency Ç׸ñÀ» ¸¸µé°Å³ª ¼öÁ¤ÇϽʽÿÀ.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
AdminSDProtectFrequency ·¹Áö½ºÆ®¸® Ç׸ñÀÌ ¾øÀ¸¸é adminSDHolder °³Ã¼°¡ 60ºÐ(3600ÃÊ)¸¶´Ù º¸¾È ¼³¸íÀÚ¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. ÀÌ ·¹Áö½ºÆ®¸® Ç׸ñÀ» ÅëÇØ ÃÊ ´ÜÀ§ °ªÀ» ÀÔ·ÂÇÏ¿© 1ºÐ(60ÃÊ)¿¡¼­ 2½Ã°£(7200ÃÊ) »çÀÌÀÇ °ªÀ¸·Î ºóµµ¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯³ª ªÀº Å×½ºÆ® ±â°£À» Á¦¿ÜÇϰí´Â ÀÌ °ªÀ» ¼öÁ¤ÇÏÁö ¾Ê´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ °ªÀ» ¼öÁ¤Çϸé LSASS ó¸® ¿À¹öÇìµå°¡ ´Ã¾î³¯ ¼ö ÀÖ½À´Ï´Ù.

Windows 2000¿¡¼­ º¸È£µÇ´Â ±×·ìÀÇ ¸ñ·ÏÀº ´ÙÀ½°ú °°½À´Ï´Ù.
  • Enterprise Admins
  • Schema Admins
  • Domain Admins
  • Administrators

Windows Server 2003 ¹× Windows 2000¿¡¼­ 327825 ÇÖÇȽº¸¦ Àû¿ëÇϰųª Windows 2000 ¼­ºñ½º ÆÑ 4¸¦ ¼³Ä¡ÇÑ ÈÄÀÇ º¸È£µÇ´Â ±×·ì ¸ñ·ÏÀº ´ÙÀ½°ú °°½À´Ï´Ù.
  • Administrators
  • Account Operators
  • Server Operators
  • Print Operators
  • Backup Operators
  • Domain Admins
  • Schema Admins
  • Enterprise Admins
  • Cert Publishers
¶ÇÇÑ ´ÙÀ½°ú °°Àº »ç¿ëÀÚµµ º¸È£µÇ´Â °ÍÀ¸·Î °£Áֵ˴ϴÙ.
  • Administrator
  • Krbtgt
¸ÞÀÏ ±×·ìÀÇ ±×·ì µî·Ï¿¡¼­´Â »ç¿ëÀÚ ÅäÅ«À» ä¿ìÁö ¾Ê½À´Ï´Ù. µû¶ó¼­ "whoami"¿Í °°Àº µµ±¸¸¦ »ç¿ëÇÏ¿© ±×·ì µî·ÏÀ» È®ÀÎÇÒ ¼ö ¾ø½À´Ï´Ù.

À§ÀÓµÈ °ü¸®¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é Active Directory °ü¸®¸¦ À§ÀÓÇÏ´Â ÃÖ»óÀÇ ¹æ¹ý ¹é¼­¸¦ ´Ù¿î·ÎµåÇϽʽÿÀ. ÀÌ ¹®¼­¸¦ ´Ù¿î·ÎµåÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/downloads/details.aspx?familyid=631747a3-79e1-48fa-9730-dae7c0a1d6d3&displaylang=en(¿µ¹®)




Microsoft Á¦Ç° °ü·Ã ±â¼ú Àü¹®°¡µé°ú ¿Â¶óÀÎÀ¸·Î Á¤º¸¸¦ ±³È¯ÇϽ÷Á¸é Microsoft ´º½º ±×·ì¿¡ Âü¿©ÇϽñ⠹ٶø´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 817433 - ¸¶Áö¸· °ËÅä: 2007³â 12¿ù 3ÀÏ ¿ù¿äÀÏ - ¼öÁ¤: 23.4
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  • Microsoft Windows Small Business Server 2003 Premium Edition
  • Microsoft Windows Small Business Server 2003 Standard Edition
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 3
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 4
Ű¿öµå:?
kbqfe kbwinserv2003sp1fix atdownload kbhotfixserver KB817433

Çǵå¹é º¸³»±â