19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

B.2 AD Documentation Examples<br />

This section of the appendix provides examples of documentation that could be used to meet requirements for compliance with the<br />

Active Directory STIG.<br />

B.2.1 Trust Relationship Documentation<br />

The following subsections provide examples of documentation to satisfy trust relationship requirements. Note that some trust<br />

attributes are relevant only to specific configurations as follows:<br />

- Selective Authentication is not applicable (N/A) for realm trusts or any incoming trusts.<br />

- SID Filtering is not applicable (N/A) for realm trusts or any incoming trusts.<br />

B.2.1.1 Example Trust Relationship Documentation - Child Domain<br />

The following example documents trust relationships for a domain that has established two unidirectional external trusts with one<br />

other domain and a realm trust with a Kerberos domain.<br />

AD Trust Relationship Documentation<br />

A. Domain NetBIOS name:_NORTH____ Verified:_Mar 2006_<br />

Fully Qualified Domain Name:__NORTH.AOFN21.DISA.MIL___________<br />

B. Classification:_Unclass____<br />

C. MAC:_II_ Confidentiality:_Sensitive__<br />

D. Trusts Defined:<br />

Type Other Party (NetBIOS\FQDN) MAC Classif. Direction Transitive Selective<br />

External MEFN19 \ MEFN19.USN.MIL II Unclass Outgoing N/A Yes Yes<br />

External MEFN19 \ MEFN19.USN.MIL II Unclass Incoming N/A N/A N/A<br />

Realm UNI91 II Unclass Outgoing No N/A N/A<br />

UNCLASSIFIED<br />

Auth<br />

SID<br />

Filtering<br />

B-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!