Exporting effective security of Server.

G

Guest

Hi,

I need to provide our security audit team with an "effective security settings" output from a selection of servers. For windows 2003 I am using a combination of RSOP with the new GPMC and gpresult, which they are happy with. However RSOP does not work with w2k and the W2k version of gpresult does not provide the security information. Therefore they are requesting a template output in .inf or .sdb form from the windows 2000 servers, so that they can compare against a predefined template (usng the security and analysis snapin). I can get this information if I perform an analysis on the actual server itself, but there seems to be no way to export these settings and audit do not have access to the servers? I have tried grabbing the local secedit.sdb file, but that only shows local setting and not those applied via GPO. So basically I am asking Is there anyway to export the effective security settings of a server to an .inf or .sdb file?

Thanks in advance if you can help.

Cheers,
Rob
 
S

Steven L Umbach

Try using secedit /export /mergedpolicy /cfg filename.inf. By not specifing
the /db it will use secedit.sdb and merged policy should show effective
settings. Not sure if it will be adequate for your needs but worth a
ry. --- Steve

http://is-it-true.org/nt/nt2000/atips/atips75.shtml

Rob said:
Hi,

I need to provide our security audit team with an "effective security
settings" output from a selection of servers. For windows 2003 I am using a
combination of RSOP with the new GPMC and gpresult, which they are happy
with. However RSOP does not work with w2k and the W2k version of gpresult
does not provide the security information. Therefore they are requesting a
template output in .inf or .sdb form from the windows 2000 servers, so that
they can compare against a predefined template (usng the security and
analysis snapin). I can get this information if I perform an analysis on
the actual server itself, but there seems to be no way to export these
settings and audit do not have access to the servers? I have tried grabbing
the local secedit.sdb file, but that only shows local setting and not those
applied via GPO. So basically I am asking Is there anyway to export the
effective security settings of a server to an .inf or .sdb file?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top