19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS10.0190 SID Filtering Trust Option<br />

STIG ID \ V-Key DS10.0190 \ V0008538<br />

Severity Cat II<br />

Short Name SID Filtering Trust Option<br />

IA Controls ECAN-1, ECCD-1, ECCD-2<br />

MAC /Conf 1-CS, 2-CS, 3-CSP<br />

References AD STIG 2.3.3.2<br />

Long Name: An outgoing external or forest trust is configured without SID filtering.<br />

Checks:<br />

Note: Currently this check can only be performed using a command line program<br />

(netdom.exe) that is installed with the Windows Support Tools. If they are not<br />

installed, this check will be Not Reviewed.<br />

A. Windows 2000 Server Procedures<br />

• Start the Active Directory Domains and Trusts console (“Start”, “Run…”,<br />

“domain.msc”).<br />

• Select the left pane item that matches the name of the domain being reviewed.<br />

- Right-click the domain name and select the Properties item.<br />

- On the domain object Properties window, select the Trusts tab.<br />

- For *each* outgoing external trust:<br />

-- At a command line prompt enter<br />

“netdom trust trusting-domain /D:trusted-domain /filtersids”<br />

where trusting-domain is the domain being reviewed<br />

and trusted-domain is the other party to the trust.<br />

• If the output of the netdom commands indicates that SID filtering is not enabled<br />

on every outgoing external trust, then this is a Finding.<br />

B. Windows Server 2003 Procedures<br />

• Start the Active Directory Domains and Trusts console (“Start”, “Run…”,<br />

“domain.msc”).<br />

• Select the left pane item that matches the name of the domain being reviewed.<br />

- Right-click the domain name and select the Properties item.<br />

- On the domain object Properties window, select the Trusts tab.<br />

- For *each* outgoing external and forest trust:<br />

-- At a command line prompt enter<br />

“netdom trust trusting-domain /D:trusted-domain /quarantine”<br />

where trusting-domain is the domain being reviewed<br />

and trusted-domain is the other party to the trust.<br />

• If the output of the netdom commands indicates that SID filtering is not enabled<br />

on every outgoing external or forest trust, then this is a Finding.<br />

UNCLASSIFIED<br />

5-19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!