Security checklist for Exact Synergy Enterprise.
The following topics can help to tighten the security of the Exact Synergy Enterprise implementation:
Top
The new process model in IIS 6.0 includes process recycling, which means an administrator can easily install the IIS patches, and new employees can process the DLLs without any service interruption.
Auto update version 1.0 provides three options for the customers, such as notify them when new patches are available, download patch(es), and notify them when the patches are downloaded, and schedule the installer. For more information, see Windows Automatic Updates in Windows Help.
The new process model in IIS 6.0 includes process recycling. This means an administrator can easily install most of the IIS patches, and new employees can process the DLLs without any service interruption.
Auto update version 1.0 provides three options to the customers such as notify them when there are new patches, download patch, and notify when the patches are downloaded, and schedule the installer. For more information, see Windows Automatic Updates in Windows Help.
a. Disable the anonymous authentication.
b. Enable the basic authentication if employees must be validated through a firewall via the proxy server.
c. Enable the Integrated Windows Authentication to validate the employees.
d. Define read rights (no write, script source access, and directory browsing).
e. Execute permissions (scripts only).
f. Application protection, such as medium (pooled), or high (isolated).
a. Enable the anonymous authentication for all the public users.
b. Enable the basic authentication if resellers, and customers must be validated through a firewall via the proxy server.
c. Enable the Integrated Windows Authentication to validate resellers, and customers.
f. Application protection such as medium (pooled), or high (isolated).
Sample
Virtual directory
Location
IIS Samples
\IISSamples
c:\inetpub\iissamples
IIS Documentation
\IISHELP
c:\winnt\help\iishelp
Data Access
\MSADC
c:\program files\common files\system\msadc
Administrators (Full Control)
System (Full Control)
Everyone (RWC)
Services needed to run IIS and MS SQL Server: Event Log, IIS Admin Service, License Logging Service, MSDTC, Protected Storage, Remote Procedure Call, (RPC) Service, Server, Windows NT Server or Windows NT Workstation, Windows NTLM Security Support, Provider, Workstation, World Wide Web Publishing Service, MSSQLServer, and/or SQL Server agent.
Services needed on the server: Certificate Authority (required to issue certificates), Content Index (required if using Index Server), FTP Publishing Service (required if using FTP service; it is highly recommended that FTP, and Web services run on different servers.), NNTP Service (required if using NNTP Service), Plug and Play (recommended, but not required), Remote Access Services (required if you use dial-up access), RPC Locator (required if doing remote administration), Server Service (can be disabled, but required to run User Manager), SMTP Service (required if using SMTP Service), Telephony Service (required if access is by dial-up connection), Uninterruptible Power Supply (UPS) (optional but it is recommended that you use a UPS), and/or Workstation (optional but important if you have UNC virtual roots).
Services not needed on the server: Alerter, ClipBook Server, Computer Browser, DHCP Client, Messenger, NetBIOS Interface, Net Logon, Network DDE & Network DDE DSDM, Network Monitor Agent, NWLink NetBIOS, NWLink IPX/SPX Compatible Transport (not required unless you do not have TCP/IP, or another transport), Simple TCP/IP Services, Spooler, TCP/IP NetBIOS Helper, and/or WINS Client (TCP/IP).
It is possible that you need other services. This depends on your network environment. For example, WINS and DHCP.
For a complete list of required services, see http://msdn.microsoft.com.
For more information on Internet Information Services 5 checklist for Microsoft, see http://technet.microsoft.com/en-us/library/cc750569.aspx.
For more information on managing Internet Information Services 6 security solution, see http://technet.microsoft.com/en-us/library/cc787186(v=ws.10).aspx.
For more information on configuring Web Server Security for Internet Information Services 7, see http://technet.microsoft.com/en-us/library/cc731278(v=ws.10).aspx.
For more information on Windows 2003 server security guide, see http://www.microsoft.com/download/en/details.aspx?id=8222.
For more information on Windows 2008 server security guide, see http://technet.microsoft.com/en-us/library/cc264463.aspx.