Article ID: 891597 - Last Review: January 30, 2007 - Revision: 3.5 How to apply more restrictive security settings on a Windows Server 2003-based cluster serverINTRODUCTIONThe Microsoft Windows Server 2003 Security Guide contains
templates that you can use to improve security for your Microsoft Windows
Server 2003-based computer. This article contains guidelines that explain how
you can enhance the security of the cluster server nodes if you apply the
templates that are described in this article. To help you apply more restrictive security settings to Windows Server 2003-based cluster server nodes without disabling ordinary cluster operations, we recommend that you use the guidelines in this article together with the information that is contained in the Windows Server 2003 Security Guide. MORE INFORMATIONBefore you apply more restrictive security settings to the
Windows Server 2003-based cluster server nodes, we recommend that you first
deploy the guidelines and the sample security templates that are provided in
the Windows Server 2003 Security Guide in a lab environment. Additionally, we
recommend that you carefully apply the security templates in an Active
Directory environment. To obtain the Windows Server 2003 Security Guide, visit the following Windows Server 2003 Security Guide Overview Web site: http://go.microsoft.com/fwlink/?LinkId=14845
(http://go.microsoft.com/fwlink/?LinkId=14845)
The following guidelines apply to the configuration of basic
clustering services. These guidelines are specific to the Enterprise
Client – Member Server Baseline template that is discussed in the
"Creating a Member Server Baseline" chapter of the Windows Server 2003 Security
Guide. When you apply the Enterprise Client - Member Server
Baseline template, follow these guidelines to make the security
settings more restrictive.Note The following guidelines do not discuss special security concerns that are specific to programs that you may run on a server cluster, such as Microsoft SQL Server or Microsoft Exchange Server, are not discussed in these guidelines. Additionally, these guidelines do not discuss security guides that are provided by other agencies, such as the National Security Agency (NSA) or the National Institute of Standards and Technology (NIST). For more information about security guides that are provided by other agencies, click the following article number to view the article in the Microsoft Knowledge Base: 885409
(http://support.microsoft.com/kb/885409/
)
Security configuration guidance support
885409
(http://support.microsoft.com/kb/885409/
)
Security configuration guidance support
For more
information about the user rights that are required by the cluster service
account, click the following article number to view the article in the
Microsoft Knowledge Base: 269229
(http://support.microsoft.com/kb/269229/
)
How to manually re-create the Cluster service account
For more information about the required
security template modifications, click the following article number to view the
article in the Microsoft Knowledge Base: 890761
(http://support.microsoft.com/kb/890761/
)
You receive an "Error 0x8007042b" error message when you add or join a node to a cluster if you use NTLM version 2 in Windows Server 2003
For more information about how to configure the
template settings, click the following article number to view the article in
the Microsoft Knowledge Base: 816580
(http://support.microsoft.com/kb/816580/
)
How to analyze system security in Windows Server 2003
REFERENCESTo view the Windows Server 2003 Security Guide, visit the
following Microsoft Web page: http://technet.microsoft.com/en-us/library/cc163140.aspx
(http://technet.microsoft.com/en-us/library/cc163140.aspx)
For more information about security settings on your Windows
Server 2003 server cluster nodes, visit the following Microsoft Web page: http://www.microsoft.com/downloads/details.aspx?FamilyID=1b6acf93-147a-4481-9346-f93a4081eea8&DisplayLang=en
(http://www.microsoft.com/downloads/details.aspx?FamilyID=1b6acf93-147a-4481-9346-f93a4081eea8&DisplayLang=en)
For more information about how to secure server clusters, visit
the following Microsoft Web site: http://technet2.microsoft.com/windowsserver/en/library/f64e46ba-2d09-4f1a-ba9c-f2b1f71821eb1033.mspx
(http://technet2.microsoft.com/windowsserver/en/library/f64e46ba-2d09-4f1a-ba9c-f2b1f71821eb1033.mspx)
| Article Translations
|
Back to the top
