117
System settings: Optional subsystems
Member Server Default
Legacy Client
Enterprise Client
High Security Client
POSIX None None None
Important:
Administrators within multi-protocol heterogeneous environments, especially within Unix
and Linux, may want to set this setting back to
POSIX
for the NAS and server systems.
The
System settings: Optional subsystems
security option setting determines which subsystems are
used to support applications within the network. The default value for this setting in Windows Server
2003 is
POSIX
. In order to disable the POSIX subsystem, this setting is configured to
None
in the
three environments defined in this guide.
2.9.4
Event Log Settings
The Event Log settings for file servers in the three environments defined in this guide are configured
via the MSBP. For more information on the MSBP, see section 2.8.
2.9.5
System Services
Any service or application is a potential point of attack, and therefore any unneeded services or
executable files should be disabled or removed. In the MSBP, optional services, as well as any
unnecessary services, are disabled. There are additional services that are often enabled on file
servers running Microsoft Windows Server 2003 that are not essential. The use and security of these
services is frequently the subject of debate. For this reason, recommendations for file servers in this
guide may not be applicable to company network environment. Adjust the File Server Group Policy
recommendations as needed to meet company requirements.
Automatic Updates
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
wuauserv Automatic Automatic Automatic Automatic
Important: Automatic Updates
must be set to
Disabled
for all HP NAS server systems.
The
Automatic Updates
system service enables the download and installation of critical Windows
updates. To ensure greater control over the installation of software updates in the three environments
defined in this guide, disable this service. Searching for, downloading, and installing applicable
critical fixes will have to be done by going to the Windows Update Web site at
http://v4.windowsupdate.microsoft.com/en/default.asp
.
Client Service for Netware
Service Name
Member Server
Default
Legacy Client
Enterprise Client High Security Client
NWCWorkstation Not
installed
Disabled Disabled Disabled
Important: Client Service for Netware
must be set to
Automatic
for all HP NAS server systems that use
Services For Netware (SFN)
The
Client Service for Netware
system service provides access to file and print resources on NetWare
networks to users interactively logged on to servers on which the service is installed. With Client
Service for Netware, administrators can access file and print resources on Netware Servers that are
running Novell Directory Services (NDS) or bindery security (NetWare versions 3.x or 4.x) from their
computer. To ensure greater security in the three environments defined in this guide, disable this
service.