ImageVerifierCode 换一换
格式:DOCX , 页数:25 ,大小:46.20KB ,
资源ID:25283850      下载积分:3 金币
快捷下载
登录下载
邮箱/手机:
温馨提示:
快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。 如填写123,账号就是123,密码也是123。
特别说明:
请自助下载,系统不会自动发送文件的哦; 如果您已付费,想二次下载,请登录后访问:我的下载记录
支付方式: 支付宝    微信支付   
验证码:   换一换

加入VIP,免费下载
 

温馨提示:由于个人手机设置不同,如果发现不能下载,请复制以下地址【https://www.bdocx.com/down/25283850.html】到电脑端继续下载(重复下载不扣费)。

已注册用户请登录:
账号:
密码:
验证码:   换一换
  忘记密码?
三方登录: 微信登录   QQ登录  

下载须知

1: 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。
2: 试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。
3: 文件的所有权益归上传用户所有。
4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
5. 本站仅提供交流平台,并不能对任何下载内容负责。
6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

版权提示 | 免责声明

本文(Module 4Securing a Web Content Management System.docx)为本站会员(b****9)主动上传,冰豆网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知冰豆网(发送邮件至service@bdocx.com或直接QQ联系客服),我们立即给予删除!

Module 4Securing a Web Content Management System.docx

1、Module 4 Securing a Web Content Management SystemModule 4: Securing a Web Content Management System Date published:February 2009Summary:This paper describes the security considerations that apply to Web Content Management (WCM) solutions in Microsoft Office SharePoint Server 2007.See Web Content Man

2、agement Training Modules ( for a complete list of the available downloads.The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not

3、 be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication.This White Paper is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION

4、 IN THIS DOCUMENT.Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanic

5、al, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation. Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressl

6、y provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. 2009 Microsoft Corporation. All rights reserved.Microsoft, Active Directory, Excel, Forefront, InfoPath,

7、 SharePoint, SQL Server, Windows, and Windows Server are trademarks of the Microsoft group of companies. All other trademarks are property of their respective owners.Table of ContentsModule 4: Securing a Web Content Management System 1Module 4 Overview 1Objectives 1Lesson 1: Securing Servers 1Protec

8、ting Servers with Firewalls 1Using Perimeter Networks 1Important Ports 2Server Hardening for Web Content Management 4Domain Trust Relationships 4File and Printer Sharing Service 4Database Communication 4Securing the Web.config File 5Microsoft Security Products 6ISA Server and Office SharePoint Techn

9、ologies 6Microsoft Forefront Security for SharePoint and Office SharePoint Technologies 6Lesson 2: Network Security 7Objectives 7Using Secure Sockets Layer 7Digital Certificates 8SSL Sessions 8Implementation Options 9Using IP Security 9IP Security Policies 10IP Filter Lists 10Filter Actions 10Typica

10、l IP Security Policy 11Service Requirements for Session State 12Session State and Office SharePoint Server 2007 12Security Measures and Session State 12Secure Authentication 12Selecting Authentication Methods 13Supporting Multiple Authentication Methods 14Supporting the Indexing Service 14Locking Do

11、wn Forms Pages 14Undesirable Anonymous Access 15The Lockdown Feature 15Review of Module 4 15Module 4 OverviewWhen you publish content to an anonymous, Internet-facing environment, you must take particular care to ensure that your servers and your network are secure. This module describes the securit

12、y considerations that apply to Web Content Management (WCM) solutions in Microsoft Office SharePoint Server 2007.ObjectivesAfter completing this module, you will be able to: Describe techniques to secure servers in an Office SharePoint Server 2007 WCM solution (Lesson 1) Describe techniques to secur

13、e network communications in a WCM server farm (Lesson 2)Lesson 1: Securing ServersWhen you deploy a WCM solution, you must often isolate your production server farm both from the Internet and from your internal network. This lesson describes some of the measures you can take to protect your servers

14、while still enabling legitimate anonymous users to access your content.ObjectivesAfter completing this lesson, you will be able to: Plan firewall configurations for a SharePoint Server 2007 WCM deployment Describe how standard server-hardening guidelines differ for WCM solutions Describe how you can

15、 use Microsoft security products to provide edge security, virus protection, and content filteringProtecting Servers with FirewallsFirewalls are devices that regulate connections between different networks, such as between the Internet and a corporate network. A properly configured firewall only per

16、mits network connections that have been explicitly allowed, based on the source and destination address, protocol, port number, and target application of a request. To protect an Internet-facing WCM solution with firewalls, you must understand the port numbers and protocols that Office SharePoint Se

17、rver 2007 uses to communicate with clients and servers. Using Perimeter Networks Important PortsUsing Perimeter NetworksA perimeter network (also known as demilitarized zone, DMZ, and screened subnet) sits between an organizations internal network and the Internet. The perimeter network typically co

18、ntains servers such as Web servers and Mail servers that you want to expose to external users. Conceptually, a perimeter network includes two firewalls: an outer firewall between the Internet and the perimeter network, and an inner firewall between the perimeter network and the internal network. In

19、practice, you are likely to use Microsoft Internet Security and Acceleration Server (ISA Server) or a similar product to manage the perimeter network and provide firewall functionality.The outer firewall is configured to allow external users to connect to specific servers in the perimeter network on

20、 specific ports. For example, your outer firewall might allow connections to your Web servers on port 80 and port 443, and connections to your Mail server on port 110. Similarly, the inner firewall is configured to allow internal users to connect to specific servers in the perimeter network on speci

21、fic ports. It also regulates any necessary network traffic from the perimeter network to the internal network. Together, the outer firewall and the inner firewall prevent external users from gaining access to servers in your internal network.If you use multiple Office SharePoint Server 2007 farms fo

22、r a WCM solution, only your production environment is typically exposed to external users. As such, you usually install the entire production server farm in your perimeter network. Your staging environment, together with development and test environments if you use them, are normally not exposed to

23、external users. For this reason, you should install staging, test, and development server farms in your internal network. To deploy content from your staging environment to your production environment, you must configure your inner firewall to permit communication from the Central Administration ser

24、ver in your staging environment to the Central Administration server in your production environment. If you share a Shared Services Provider (SSP) across a firewall, you must configure the firewall to permit communication on various ports for different services.Finally, you should note that the reco

25、mmended server farm layouts described here for WCM solutions differ from recommended server farm layouts for other Office SharePoint Server 2007 solutions, where you are more likely to deploy Web servers in a perimeter network with Application servers and Database servers in an internal network.Impo

26、rtant PortsThe servers in an Office SharePoint Server 2007 server farm communicate on several different ports. If this communication occurs across a firewall, you must configure the firewall to permit communication on that particular port. The following table lists the ports that Office SharePoint S

27、erver 2007 requires for various functions.FunctionFrom/ToPortsClient access External users to Web servers Internal users to Web servers TCP port 80 TCP port 443 (SSL)Remote administration Terminal Services jump point to all servers RDP (TCP 3389)Administrator access to Central Administration Interna

28、l users to Web server that hosts the Central Administration Web site Configured on installationFile and printer sharing service Web servers to Query servers (search requests) Index servers to Query servers (index propagation) TCP/UDP port 445 (SMB) (recommended)or TCP/UDP ports 137, 138, and 139 (Ne

29、tBIOS)Office Server Web services Web servers to Query servers Web servers to Index server Web servers to Excel Calculation Services host Index server to Query servers Query servers to Index server TCP port 56737or TCP port 56738 (SSL) (configured per SSP)Database communication All Office SharePoint

30、servers (regardless of role) to Database servers TCP port 1433 UDP port 1434 Note: You should reassign these ports. This is described in the next section, “Server Hardening for Web Content Management.”SSO service From any server role that hosts the single sign-on (SSO) service to the encryption key

31、server TCP port 135 Restricted high ports (for static RPC) or random high ports (for dynamic RPC)Document conversions Web servers to document conversions services host TCP port 8082 (Document Conversions Launcher Service) TCP port 8093 (Document Conversions Load Balancer Service)Index crawls Index s

32、erver to web servers (or dedicated crawl server Index server to other content sources TCP port 80 TCP port 443 (SSL) Other content source-appropriate portsAuthentication and DNS ALL Office SharePoint servers to DC and DNS servers DS (TCP 445) RPC (TCP 135) DNS (UDP 53) Kerberos (UDP 88)Outbound Email Web servers to SMTP and

copyright@ 2008-2022 冰豆网网站版权所有

经营许可证编号:鄂ICP备2022015515号-1