16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

714 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

6. Remove the 3.5-inch disk from the disk drive.<br />

Note Restoring the encryption key <strong>and</strong> re-encrypting the single sign-on credentials<br />

store with the restored key is a long-running process. It is recommended<br />

that you restore the encryption key during non-peak periods.<br />

Enabling Auditing for the Encryption Key<br />

You should enable auditing for the encryption key. Then, if the key is read or written<br />

to, there will be an audit trail in the security log in <strong>Microsoft</strong> Windows<br />

Server 2003 Event Viewer.<br />

To enable auditing for the encryption key, you need to modify the registry<br />

using regedit <strong>and</strong> then enable auditing using Group Policy Object Editor.<br />

1. To modify the registry, do the following:<br />

a. On the taskbar, click Start, <strong>and</strong> then click Run.<br />

b. Type regedit <strong>and</strong> then click OK.<br />

c. In Registry Editor, navigate to HKEY_LOCAL_MACHINE\SOFTWARE<br />

\<strong>Microsoft</strong>\ssosrv\Config.<br />

d. Right-click Config, <strong>and</strong> then click Permissions.<br />

e. In the Permissions for Config dialog box, click Advanced.<br />

f. In the Advanced Security Settings for Config dialog box, click the<br />

Auditing tab, <strong>and</strong> then click Add.<br />

g. In the Select User, Computer, or Group dialog box, in the Enter the<br />

object name to select box, type everyone.<br />

h. Click OK.<br />

i. In the Auditing Entry for Config dialog box, in the Failed column,<br />

select the Full Control check box, <strong>and</strong> then click OK.<br />

j. Click OK, <strong>and</strong> then click OK again to close all dialog boxes.<br />

k. Close Registry Editor.<br />

To enable auditing, do the following:<br />

1. On the taskbar, click Start, <strong>and</strong> then click Run.<br />

2. Type mmc <strong>and</strong> then click OK.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!