19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

<strong>Recommended</strong> <strong>Baseline</strong> <strong>Security</strong> (ITSG-20)<br />

23. Select “Yes” if you wish to save the settings.<br />

a. Otherwise, select “No”.<br />

4.2 <strong>Baseline</strong> <strong>Server</strong> Policy Files Details<br />

The following section provides additional services and settings that are managed by policy files.<br />

The Domain and Workgroup <strong>Baseline</strong> configuration files are largely identical. The following<br />

section provides details on the security settings. Items that are not the same will have both<br />

settings documented.<br />

4.3 Account Policies<br />

Account policies determine the rules for user’s with respect to passwords and Kerberos.<br />

4.3.1 Password Policy<br />

4.3.1.1 Enforce password history<br />

PasswordHistorySize = 24<br />

The ‘PasswordHistorySize’ defines the number of passwords retained by the system. This<br />

history is compared with user input during password changes. The setting ‘24’ requires the user<br />

to select twenty-four unique passwords before they can re-use their first one. With a<br />

‘MinimumPasswordAge’ of two, the user would have to cycle their password every two days to<br />

get back to their original password.<br />

4.3.1.2 Maximum password age<br />

MaximumPasswordAge = 42<br />

The ‘MaximumPasswordAge’ defines the maximum number of days a user can keep the same<br />

password. A setting of forty-two requires the user to change their password every forty-two days.<br />

Combined with the ‘PasswordComplexity’ and ’PasswordLength’ settings, these settings ensure<br />

the password is strong and resilient to attack.<br />

4.3.1.3 Minimum Password Age<br />

MinimumPasswordAge = 2<br />

The ‘MinimumPasswordAge’ defines how many days a user must wait between password<br />

changes. The setting ‘2’ requires the user to wait two before they can change it again.<br />

4.3.1.4 Minimum password length<br />

MinimumPasswordLength = 8<br />

The ‘MinimumPasswordLength’ defines the minimum number of characters acceptable for a<br />

password. The setting ‘8’ requires the user to enter a password of eight characters or more.<br />

<strong>Server</strong> Policy Files March 2004 45

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!