<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosting Open Forum</title><link>http://forums.asp.net/158.aspx</link><description>General discussions concerning ASP.NET in a Windows Hosting environment</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Security Templates for GPOs</title><link>http://forums.asp.net/thread/732396.aspx</link><pubDate>Fri, 29 Oct 2004 05:21:47 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:732396</guid><dc:creator>mkostersitz</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/732396.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=158&amp;PostID=732396</wfw:commentRss><description>No you should disable them first so that the Servers pick up the reversion of the settings if you just delete them the 'old' settings are left behind.
&lt;br /&gt;

&lt;br /&gt;
Mike</description></item><item><title>Re: Security Templates for GPOs</title><link>http://forums.asp.net/thread/730544.aspx</link><pubDate>Wed, 27 Oct 2004 13:47:12 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:730544</guid><dc:creator>DmitriG</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/730544.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=158&amp;PostID=730544</wfw:commentRss><description>Thank you, guys.
&lt;br /&gt;

&lt;br /&gt;
Does it mean that I can safely delete all this GPOs?
&lt;br /&gt;

&lt;br /&gt;</description></item><item><title>Re: Security Templates for GPOs</title><link>http://forums.asp.net/thread/730316.aspx</link><pubDate>Wed, 27 Oct 2004 07:12:23 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:730316</guid><dc:creator>mkostersitz</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/730316.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=158&amp;PostID=730316</wfw:commentRss><description>THanks for point this out. 
&lt;br /&gt;

&lt;br /&gt;
The Templates are not required to run Hosted Exchange they are samples and mea culpa faulty ones. 
&lt;br /&gt;

&lt;br /&gt;
I will fix the templates sometime soon and we will release an update.
&lt;br /&gt;

&lt;br /&gt;
HTH</description></item><item><title>Re: Security Templates for GPOs</title><link>http://forums.asp.net/thread/729907.aspx</link><pubDate>Tue, 26 Oct 2004 19:33:18 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:729907</guid><dc:creator>jjstreic</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/729907.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=158&amp;PostID=729907</wfw:commentRss><description>I don't believe the templates are required for running Hosted Exchange.  That being said they do have some appropriate security settings that you should evaluate deploying with your infrastructure.
&lt;br /&gt;

&lt;br /&gt;
I'm checking on the template reg key issue.  It has been a long time since I have worked directly with templates so I am setting up a lab.  I'll get back to you on that.
&lt;br /&gt;

&lt;br /&gt;
I have sent the product team your comments on the Domain Controller policy issue.  I checked the documentation and I don't see any mention of prioritizing the policies either.  I have sent this question back to the product team for comment.
&lt;br /&gt;

&lt;br /&gt;
Thanks!
&lt;br /&gt;</description></item><item><title>Security Templates for GPOs</title><link>http://forums.asp.net/thread/727214.aspx</link><pubDate>Fri, 22 Oct 2004 22:02:50 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:727214</guid><dc:creator>DmitriG</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/727214.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=158&amp;PostID=727214</wfw:commentRss><description>Greetings,
&lt;br /&gt;

&lt;br /&gt;
According to “Solutions for Windows-based Hosting with Hosted Exchange 2003” (Volume 6, Book 2) we create couple GPO and import based on Security Templates (DomainControllerV1.inf, mpsserver01.inf, etc.). Then we link those GPO’s  to OU’s using GPMC. After moving computers to corresponding OU and applying GPO we receive Warning events in application log:
&lt;br /&gt;

&lt;br /&gt;
Source: SceCli
&lt;br /&gt;
Event ID: 1202
&lt;br /&gt;
Type: Warning
&lt;br /&gt;
Description: Security policies were propagated with warning. 0xd : The data is invalid.
&lt;br /&gt;

&lt;br /&gt;
This event exists on ALL computers in reference infrastructure, so I will talk only about domain controller as an example because I think the root reason for this warning is the same for ALL Security Templates.
&lt;br /&gt;

&lt;br /&gt;
In winlogon.log file I found this messages:
&lt;br /&gt;

&lt;br /&gt;
----Configure Security Policy...
&lt;br /&gt;
	Configure password information.
&lt;br /&gt;
	Configure account force logoff information.
&lt;br /&gt;
	Guest account is disabled.
&lt;br /&gt;

&lt;br /&gt;
	System Access configuration was completed successfully.
&lt;br /&gt;
	LSA anonymous lookup names setting : existing SD = D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS).
&lt;br /&gt;
	Configure LSA anonymous lookup setting.
&lt;br /&gt;
	Configure log settings.
&lt;br /&gt;

&lt;br /&gt;
	Audit/Log configuration was completed successfully.
&lt;br /&gt;

&lt;br /&gt;
	Kerberos Policy configuration was completed successfully.
&lt;br /&gt;
	Configure hkey_local_machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
&lt;br /&gt;
Warning 3: The system cannot find the path specified.
&lt;br /&gt;
 	Error configuring hkey_local_machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
&lt;br /&gt;
	Configure hkey_local_machine\system\currentcontrolset\control\lsa\nolmhash.
&lt;br /&gt;
Warning 3: The system cannot find the path specified.
&lt;br /&gt;
 	Error configuring hkey_local_machine\system\currentcontrolset\control\lsa\nolmhash.
&lt;br /&gt;
	Configure hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
&lt;br /&gt;
Warning 3: The system cannot find the path specified.
&lt;br /&gt;
 	Error configuring hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
&lt;br /&gt;
	Configure hkey_local_machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
&lt;br /&gt;
Warning 3: The system cannot find the path specified.
&lt;br /&gt;
 	Error configuring hkey_local_machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\control\lsa\nolmhash.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\services\netlogon\parameters\requiresignorseal.
&lt;br /&gt;
	Configure machine\system\currentcontrolset\services\ntds\parameters\ldapserverintegrity.
&lt;br /&gt;

&lt;br /&gt;
	Configuration of Registry Values was completed with one or more errors.
&lt;br /&gt;

&lt;br /&gt;
To solve this problem I deleted WH-Domain controller GPO, updated DomainControllerV1.inf security template by replacing string “HKEY_LOCAL_MACHINE” with “MACHINE”, and recreate WH-Domain controller GPO using updated template. So, it solved the problem with Warning in event log on domain controller (and I think it will solve problem on other computers), but I figured out another problem on domain controller.
&lt;br /&gt;

&lt;br /&gt;
Almost all settings for Computer configuration\Windows settings\Local policies\ Security options in WH-Domain controller GPO are ineffective because Default Domain Controllers Policy GPO has higher priority than WH-Domain controller GPO (because of the procedure how to create and link policy to OU). For example Domain Controller: LDAP server signing requirements:
&lt;br /&gt;

&lt;br /&gt;
Default Domain Controllers Policy: None
&lt;br /&gt;
WH-Domain controller: Require signing 
&lt;br /&gt;
Effective setting: None
&lt;br /&gt;

&lt;br /&gt;
Here are a couple of questions: 
&lt;br /&gt;
1.	Should I worry about those GPO’s or I should live it as is?
&lt;br /&gt;
2.	How those policies affects hosting environment?
&lt;br /&gt;
3.	If this issue is critical then how to fix it?
&lt;br /&gt;

&lt;br /&gt;
Regards,
&lt;br /&gt;

&lt;br /&gt;
Dmitri Gaikovoi
&lt;br /&gt;</description></item></channel></rss>