ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload
ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload
ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Active Directory Checklist, V1R1.2 Field Security Operations<br />
22 September 2006 Defense Information Systems Agency<br />
5.4 Active Directory Forest<br />
Notes: The checks in this section apply to Active Directory Forest assets and are performed on<br />
only one or two domain controllers per AD forest according to forest configuration as<br />
follows:<br />
- DS10.0230 applies only for Windows Server 2003 and must be done on that platform.<br />
- DS10.0295 applies only to the domain controller that holds the authoritative time source<br />
for the forest. When the Windows Time service is used, that is the root domain<br />
controller that holds the PDC Emulator FSMO role.<br />
The checks in this section address some forest-specific characteristics that affect the level of<br />
security within an AD forest.<br />
DS10.0230 dsHeuristics Option [Windows Server 2003 only]<br />
STIG ID \ V-Key DS10.0230 \ V0008555<br />
Severity Cat II<br />
Short Name dsHeuristics Option<br />
IA Controls ECAN-1, ECCD-1, ECCD-2<br />
MAC /Conf 1-CS, 2-CS, 3-CSP<br />
References AD STIG 2.3.3.4<br />
Long Name: The dsHeuristics option is not configured to prevent anonymous access to AD.<br />
Checks:<br />
Note: This check is Not Applicable for domains that contain no Windows Server<br />
2003 domain controllers.<br />
This check must be performed on a Windows Server 2003 domain controller.<br />
• At a command line prompt enter (on a single line):<br />
“dsquery * "cn=directory service,cn=windows nt,cn=services,<br />
cn=configuration,dc=forest-name" -attr *”<br />
where forest-name is the fully qualified LDAP name of the<br />
root of the domain being reviewed.<br />
• If the dsHeuristics attribute is listed, note the assigned value.<br />
• If the dsHeuristics attribute is defined and has a “2” in the seventh character, then<br />
this is a Finding.<br />
Note: An example of the dsquery command for the vcfn.disaost.mil forest is:<br />
dsquery * "cn=directory service,cn=windows nt,cn=services,<br />
cn=configuration,dc=vcfn,dc=disaost,dc=mil" -attr *<br />
Note: Examples of values that would be a Finding are: “0000002”, “0010002”,<br />
“0000002000001”.<br />
UNCLASSIFIED<br />
5-29