22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

366 Lotus Security Handbook<br />

precautions for any services that are intended to run on the IT system. After all, it<br />

does not help to harden the base operating system and leave gaping holes in the<br />

Web or database server installations. It’s worth repeating that every product<br />

installed on the operating system has the potential to allow intruders to gain<br />

access to that IT system.<br />

9.3.1 Hardening Windows NT 4.0<br />

Windows NT 4.0 has been the workhorse for Microsoft for years now. And<br />

although there are more feature-rich replacements now available, there are<br />

many reasons why Windows NT 4.0 might still be deployed. The fact that most<br />

customers have established a stable and secure baseline is one of the most<br />

common ones. Therefore, hardening guidelines for the elderly flagship product<br />

are discussed first. Many options apply to newer version of Windows as well, so<br />

reading through this section is recommended.<br />

Hardening installation guidelines<br />

When installing Windows NT 4.0 Server, it is best to follow the guidelines<br />

presented here as closely as possible. Some of these changes might go so far as<br />

removing a needed functionality that an application requires. If this is the case,<br />

hard choices will have to be made. For instance, if the functionality must be kept<br />

in, the system administrators will have to work harder to protect the server,<br />

perhaps using some of the tools and techniques mentioned earlier in the chapter.<br />

Installation do’s<br />

Let’s begin with what should be done, and save the discussion of what shouldn’t<br />

be done for a little bit later. This ensures that some best practices can be<br />

developed and that the proper things are installed. It is better to start off with a<br />

proper base than to have to correct an improper installation later.<br />

So, for security purposes, the following are the things you should do when<br />

installing Windows NT 4.0.<br />

► Install the NTFS file system, not FAT. NTFS provides additional security<br />

controls via access control lists (ACLs) and is a more robust file system.<br />

Note: Some system administrators prefer to install the FAT file system and<br />

then convert to the NTFS file system after installation. This is not<br />

recommended because this will not apply the default ACLs.<br />

► Install as a standalone server, and do not install as a domain controller<br />

(unless there are some significant reasons to). That way, there is no<br />

conceivable need to have a firewall or DMZ Web, Domino, or DNS server<br />

participate in a domain.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!