Presentation is loading. Please wait.

Presentation is loading. Please wait.

IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.

Similar presentations


Presentation on theme: "IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication."— Presentation transcript:

1 IS 4506 Windows NTFS and IIS Security Features

2  Overview Windows NTFS Server security Internet Information Server security features Securing communication with IIS Configuring SSL Digital Certificates

3 Windows 2000 Server Security Recommendations Securing User Accounts and Groups Allow anonymous access with Internet guest account Require users to choose difficult passwords Limit administrator accounts Applying Strict Account Policies Securing Resource Access - NTFS Permissions IIS Security Checklist

4 File Systems Operations Access Permissions (Page 134)

5 NTFS Permissions (Page 134) Five standard types of permissions: Full Control No Access Read Change Special Access

6

7

8

9

10 Other Windows NTFS Security Measures Limit the number of protocols the network adapter cards use. Use the Bindings tab in the Network Program in Control Panel to unbind any unnecessary services or protocols. Turn off the Windows NT Server Service on the IIS Server to prevent users from viewing shares. Use NT Filtering

11  Access Control with IIS Web access control IP access and domain name restrictions Anonymous access and authentication control Authentication methods Web Server permissions for files and directories NTFS permissions

12 Security Requirements for Internet Servers Authentication of users Resource access control Encrypted communication Auditing and logging

13 Web Server Permissions for Files and Directories

14 Authentication Methods

15 Anonymous Access and Authentication Control Anonymous Access has user-applied restrictions Authentication Control denies access and then queries the user for authentication Name: Password: Name: Password: Xxxx xxxxxxxx

16 IP Access and Domain Name Restrictions

17 Web Access Control Access denied Access granted IP address permitted? User permitted? Web server permissions allow access? Web server permissions allow access? NTFS permissions allow access? NTFS permissions allow access? Web server receives request No Yes

18 Review Windows NT Server security recommendations Security requirements for Internet servers Access control with IIS Securing communication with IIS

19 Lab 9: Restricting Access to a Web Site

20 Review Windows 2000 Server security recommendations Security requirements for Internet servers Access control with IIS Securing communication with IIS


Download ppt "IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication."

Similar presentations


Ads by Google