19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS10.0280 Site Link Replication Properties<br />

STIG ID \ V-Key DS10.0280 \ V0008553<br />

Severity Cat III<br />

Short Name Site Link Replication Properties<br />

IA Controls ECAN-1, ECCD-1, ECCD-2<br />

MAC /Conf 1-CS, 2-CS, 3-CSP<br />

References AD STIG 2.3.3.7<br />

Long Name: An AD site link is defined with schedule and replication interval properties that<br />

prevent daily AD replication.<br />

Checks:<br />

• Start the Active Directory Sites and Services console (“Start”, “Run…”,<br />

“dssite.msc”).<br />

• Select and expand the Sites item in the left pane.<br />

- Select and expand the Inter-Site Transports item and the IP item in the left pane<br />

- For *each* site link that is defined:<br />

-- Right-click the site link item and select the Properties item<br />

-- Note the interval indicated in the “Replicate every” field<br />

-- Select the Change Schedule button.<br />

-- Using the values indicated for “Replication Available”, determine if the<br />

replication interval would allow daily replication to occur. [See note below.]<br />

-- Select the Cancel button for the Schedule window.<br />

-- Select the Cancel button for the Properties window.<br />

• If the replication interval and replication available properties do not allow daily<br />

replication, then this is a Finding.<br />

Note: An AD instance may have no AD site links defined.<br />

Note: The following are ways in which site link properties would prevent daily AD<br />

replication:<br />

- Setting the “Replicate every” value to a number greater than 1440 (the number of<br />

minutes in one day)<br />

- Setting the Schedule value for all hours in a day to “Replication Not Available”.<br />

UNCLASSIFIED<br />

5-27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!