|
tshinder -> RE: Discussion about part 1 of the SBS install series (29.Aug.2005 10:44:00 AM)
|
quote: Originally posted by dvord: Tom,
Honestly I'm very surprised and a bit disappointed that isaserver.org is going to be supportive of SBS.
MVP's have come right out and said that SBS's implementation, forcing administrators to run the Domain Controller on the same machine as the ISA Server is nothing less than watching a car crash in slow motion.
Most security folks understand that the most secure environment has key systems like firewalls and proxy servers located away from business-critical functions like collaboration applications (Exchange), and business organization functions (like AD, File and Print, etc.). By design, SBS flies in the face of conventional security. What makes matters worse is that Microsoft is frequently the target of attacks by hackers. Turning a bad situation ugly by putting vulnerable systems all together in one package.
I have posted several questions regarding SBS on Microsoft's own news server on support of this product and I'm frequently told by MVP's that "oh you shouldn't run a public website on SBS", or stating that other features which Microsoft MARKETS with SBS aren't to be used because they are flawed or highly problematic. This is not indicative of a healthy, secure system.
Security advocates have a responsibility to the people who listen to them, and ultimately to the greater good at large.
Is SBS now secure enough that concerns about ISA being on the DC are no longer valid? Wouldn't you agree that if Microsoft is marketing a critically flawed product, it is a disservice to the administrative community (and IT consumers at large) to give it "time" from such a well-recognized authority such as yourself?
Hi D,
Its true that SBS represents a security compromise. But given the large and increasing installed base, it seems to me that the best approach is help those folks secure their installations as much as possible.
Many of us have encouraged MS to unbundle an ISA and Windows lic for a single white box install of ISA, but those requests fall on deaf ears
Thanks! Tom
|
|
|
|