Jump to content

Recommended Posts

Posted

I am working on setting up software restriction for the pupils here, currently this is being done in a Test OU and a Test Pupil user which was copied from an existing user.

 

Up until yseterday things were going fine with it set to only allow the applications that I explicitly specified - down to the actual filename, or to a group of files in a folder.

 

But now I am having problems in that when I add a new "allowed" application to the list and then login with the test user, it is refusing to acknowledge that the program is now trusted for use.

 

the settings thus far are:

 

Disallow by default

 

=======

WORKING

=======

Name Type Security Level

C:\program files\microsoft office\office\*.exe Path Unrestricted

C:\program files\internet explorer\iexplore.exe Path Unrestricted

C:\program files\Crocodile Clips\Crocodile Technology 1.6\*.exe Path Unrestricted

\\mhs-pdc\NETLOGON\*.bat Path Unrestricted

C:\Windows\explorer.exe Path Unrestricted

C:\windows\system32\winlogon.exe Path Unrestricted

C:\windows\system32\userinit.exe Path Unrestricted

C:\windows\system32\rundll32.exe Path Unrestricted

\\mhs-pdc\kudos\kudos.exe Path Unrestricted

C:\Program Files\Grisoft\AVG7\*.exe Path Unrestricted

==========

NOT WORKING

==========

C:\program files\Corel\Corel Graphics 11\Programs\*.exe Path Unrestricted

C:\Program Files\Adobe\Photoshop 7.0\*.exe Path Unrestricted

C:\Program Files\Adobe\Acrobat 7.0\Reader\*.exe Path Unrestricted

C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\*.exe Path Unrestricted

C:\Program Files\Winzip\*.exe Path Unrestricted

C:\Pogram Files\Macromedia\Dreamweaver MX\Dreamweaver.exe Path Unrestricted

C:\Pogram Files\Macromedia\Dreamweaver MX\JVM\bin\*.exe Path Unrestricted

C:\windows\system32\*.exe Path Unrestricted

 

-

 

Is there something I'm doing wrong?

Posted
did you wait for the policies to update or do a gpupdate /force (xp only) or a secedit /refreshpolicy machine_policy /enforce and secedit /refreshpolicy user_policy /enforce (2000) to make sure the policies were updated?
Posted
Using 2k3 server, and ran gpupdate after changing the settings , the user is logged out unless I am testing policy changes, so when i log iin it picks up the new policies - just not the new program restrictions anymore - which it used to do
Posted

Still not getting this to work

Checked the event log of the target machine, and I am getting the following error.

 

Event Type: Error

Event Source: Userenv

Event Category: None

Event ID: 1054

Date: 17/01/2006

Time: 09:44:47

User: NT AUTHORITY\SYSTEM

Computer: IT-TESTBED

Description:

Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

 

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

 

Any suggestions?

Posted

I can get in before Dos_Box and say... "it's a DNS issue!"

 

If you look at the part that reads:

DNS test . . . . . . . . . . . . . : Passed

PASS - All the DNS entries for DC are registered on DNS server '10.4.28.200' and other DCs also have some of the names registered.

[WARNING] The DNS entries for this DC are not registered correctly on DNS server '10.1.198.65'. Please wait for 30 minutes for DNS server replication.

PASS - All the DNS entries for DC are registered on DNS server '10.4.24.200' and other DCs also have some of the names registered.

 

It looks like you have a DNS replication problem which can cause problems like this to occur. Check that zone transfers are allowed between servers and try forcing a manual replication to see if that helps.

Posted

Yeah was finding replication errors all over the place, found out why..

the RJ45 wall socket for the BDC had failed, and no one had noticed! :roll:

dont know hwen it was but was at leasat 60 days ago, so the PDC was not wanting to talk to the BDC anymore - spent ages trying to get the replications back up and running - hopefully cracked it - AD-UC is now replicating over, will check DNS, etc tomorrow...

Posted

You are going to have problems with the macromedia suite. In the college i administer i found that dreamweaver spawns a process in the users temp folder, called something similar to (random each time) ~edb112.tmp

 

Currently this means students can write to this folder and run anything. :'(

Posted

As far as I explored, there wasn't. I have taken the "security through obscurity" approach and ignored the problem and not talked about it :).

 

The director of ICT here has said any problems from it and its an admin thing (get parents in etc) we can reclone a pc using symantec ghost (that was fun gettin it set up :D) so its not a major problem.

Posted

It stores the files wherever the TEMP environment variable is set to, if you can change this to a place less obvious, or that is cleared out often or a network share where EXE's are disabled to be stored (file screening on a hp nas or windows server R2's file screening) this will obviously add network traffic, and slow down dreamweaver as its accessing a network place.

 

Thinking about it you could set the temp folder to their document or profile folder with the file screening on, however 16bit or some older software will become affected by this change... not good. i remember now i tried changing it and lots of our maths software stopped working.

Posted

I would really advise against fiddling with the temp environment variables unless you really need to as I've had lots of problems with it.

 

Ben

Posted

OK, deleted the GPO and recreated it

all ok with the stuf on the desktop (eg word & IE-)

however.. launch them from the start menu - disallowed!!

using local paths as the rules. pupil using a mandatory profle..

 

any ideas?

 

wondering if its cos of the local links but not sure how to use the registry as the links..

Posted
Had been thinking about that but just tried on a test user withno mandatory profile - same problem - any shortcut on the desktop will run if its in the allowed list, but same program wont run from start menu
Posted

Is the location of the start menu allowed? for example c:\documents and settings\username\start menu\ for unrestricted rights?

 

the LNK start menu files need to be in a place that SRP has unrestricted access.

Posted

Thanks fooby - added the .LNK filetype and that sorted it!

Set up folder redirection on the start menu and the desktop as well which is working a dream

still getting an error with CScript.exe but reckon I need to open up the .VBS files to allow them to run.

A few more tweaks and it'll be ready to roll out

 

Their profile are locked down as tight as possible - start menu only has "Programs" and "Log off " context menu removed from desktop, start menu and task bar, notification area gone access to all drives and network shares (bar one on the desktop)

Posted
@Gatt: When you get it perfected you should post the policy settings (export an HTML document using GPMC) so that others can learn from your experience.
Posted

Will do ric, may be a few weeks til I'm happy that all the software I need is in place on the policy and that the "bugs" have been worked out

the Plan is to implement it around the half-term break in Feb

Posted
Did you install Office with the option to use MSI shortcuts? (i think it does this by default) If so i am going to hazard a guess that you havent allowed the location where the shortcuts point to access to run, but hte shortcuts on the desktop will probably be "normal" shortcuts so do not suffer the same problem.
Posted

@E1uSiV3 - I got Office sorted - had to un-restrict the .LNK files

 

however, I still cannot get CSCRIPT.EXE to run even though I have authorised it to run along with VBS script files..

 

I'm attaching a copy of my curent GPO policy settings - however this is not yet complete as i am going to try and limit the list of programs further and also start adding Favourites URLs

 

It is a highly restricted profile for the students so i wont be flavour of the month with them when i implement it in a few weeks time!

 

You can use these settings yourselves but please let me know of any improvements you think could be made to the policy

test_pupil_gpo.htm

Posted

The only problem with unrestricting the *.lnk part, is, i have an exe on my usb stick, all i need to do is create a shortcut to that exe on the stick (or user folder / home dir etc) then it will become allowed.

 

What you should do, is

 

unrestricted access to \\server\share\startmenu\

which is a read only share, or unrestricted access to whereever the start menu files are.

 

fooby

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...