Windows 2000 and Windows Server 2003 policy settings
The following list contains the applicable policies for a default Windows Server 2003 installation (depending on inheritance blocking and on the "no override" settings). You must restart the domain controller for these settings to take effect because they are enforced during service startup:
- Local Security Policy (domain controller)
- Default Domain Policy
- Default Domain Controllers Policy
The following relevant policy settings may vary depending on your specific
installation requirements and configuration. To access the appropriate settings in Group Policy Management, follow these steps:
- Click Start, click Run, type gpedit.msc, and then click OK.
- Expand Computer Configuration, expand Windows Settings, expand Security Settings, expand Local Policies, and then clickSecurity
Options.
- Configure the security settings of the following policies.
- Windows 2000
- Double-click Digitally sign server communications (always), and then click Disabled.
- Double-click LAN Manager authentication level, and then click one of the following options:
- Send LM & NTLM responses
- Send LM & NTLM - use NTLMv2 session security if negotiated
- Send NTLM response only
- Windows Server 2003
- Double-click Microsoft network server: Digitally sign communications (always)
, and then click Disabled.
- Double-click Network security: LAN Manager authentication level
, and then click one of the following options:
- Send LM & NTLM responses
- Send LM & NTLM - use NTLMv2 session security if negotiated
- Send NTLM response only
Novell 6 (Service Pack 2) CIFS properties
Configure the settings for the
ConsoleOne server Properties CIFS tab according to the following example. In this example, square brackets indicate edit controls. Items in italic indicate placeholders. Items in parentheses are informational comments. Do not put these comments in the controls.
The CIFS Config tab
To configure the Novell server to use an authentication method that matches the Windows 2000 policy requirements, use the following settings:
- Server
Name: [Novell-server_w]
- Comment: [server comment text]
- WINS Address: [domain controller IP address (optional value:) Unicode (optional value:) OpLocks]
- Authentication
Mode: [Domain]
- Domain name: [NetBIOS domain name (less than 16 characters in length)]
- Primary Domain Controller
Name: [NetBIOS domain controller name]
- Address: [domain controller IP address]
The CIFS Shares tab
For example:
[SYS:\' 'sharename' 0 'sharename']