19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

5.4 Active Directory Forest<br />

Notes: The checks in this section apply to Active Directory Forest assets and are performed on<br />

only one or two domain controllers per AD forest according to forest configuration as<br />

follows:<br />

- DS10.0230 applies only for Windows Server 2003 and must be done on that platform.<br />

- DS10.0295 applies only to the domain controller that holds the authoritative time source<br />

for the forest. When the Windows Time service is used, that is the root domain<br />

controller that holds the PDC Emulator FSMO role.<br />

The checks in this section address some forest-specific characteristics that affect the level of<br />

security within an AD forest.<br />

DS10.0230 dsHeuristics Option [Windows Server 2003 only]<br />

STIG ID \ V-Key DS10.0230 \ V0008555<br />

Severity Cat II<br />

Short Name dsHeuristics Option<br />

IA Controls ECAN-1, ECCD-1, ECCD-2<br />

MAC /Conf 1-CS, 2-CS, 3-CSP<br />

References AD STIG 2.3.3.4<br />

Long Name: The dsHeuristics option is not configured to prevent anonymous access to AD.<br />

Checks:<br />

Note: This check is Not Applicable for domains that contain no Windows Server<br />

2003 domain controllers.<br />

This check must be performed on a Windows Server 2003 domain controller.<br />

• At a command line prompt enter (on a single line):<br />

“dsquery * "cn=directory service,cn=windows nt,cn=services,<br />

cn=configuration,dc=forest-name" -attr *”<br />

where forest-name is the fully qualified LDAP name of the<br />

root of the domain being reviewed.<br />

• If the dsHeuristics attribute is listed, note the assigned value.<br />

• If the dsHeuristics attribute is defined and has a “2” in the seventh character, then<br />

this is a Finding.<br />

Note: An example of the dsquery command for the vcfn.disaost.mil forest is:<br />

dsquery * "cn=directory service,cn=windows nt,cn=services,<br />

cn=configuration,dc=vcfn,dc=disaost,dc=mil" -attr *<br />

Note: Examples of values that would be a Finding are: “0000002”, “0010002”,<br />

“0000002000001”.<br />

UNCLASSIFIED<br />

5-29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!