ccms 6.0 security templates

157
Nortel – Enterprise Networks Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02 October 29, 2008 ABSTRACT This guide describes the generic Windows Server 2003 security templates for the Nortel Contact Center 6.0 suite of servers. This guide also provides the guideline and how to deploy the security template to secure the Nortel Contact Center 6.0 suite of servers. NOTICE TO HOLDERS OF PAPER COPIES: Upon receipt of a new issue, destroy the previous issue or mark it “OBSOLETE”. CONFIDENTIAL INFORMATION: The information contained in this document is the property of Nortel Networks. Except as specifically authorized in writing by Nortel Networks, the holder of this document shall keep all information contained herein confidential and shall protect same in whole or in part from disclosure and dissemination to all third parties.

Upload: pcscarey

Post on 09-Mar-2015

435 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: CCMS 6.0 Security Templates

Nortel – Enterprise Networks

Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02 October 29, 2008

ABSTRACT

This guide describes the generic Windows Server 2003 security templates for the Nortel Contact Center 6.0 suite of servers. This guide also provides the guideline and how to deploy the security template to secure the Nortel Contact Center 6.0 suite of servers.

NOTICE TO HOLDERS OF PAPER COPIES: Upon receipt of a new issue, destroy the previous issue or mark it “OBSOLETE”.

CONFIDENTIAL INFORMATION: The information contained in this document is the property of Nortel Networks. Except as specifically authorized in writing by Nortel Networks, the holder of this document shall keep all information contained herein confidential and shall protect same in whole or in part from disclosure and dissemination to all third parties.

Page 2: CCMS 6.0 Security Templates

Trademarks Nortel Proprietary

ii Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Trademarks

The following are trademarks of Nortel Networks: Nortel, Nortel Networks, BNR, ACD, BCS, CallPilot, DMS, DMS-100, DMS-250, DMS-MTX, DMS-SCP, DNC, DPN-100, DVS, DualMode, FastView, Helmsman, M2317, MAP, Symposium, Meridian Digital Centrex (MDC), Meridian, Meridian 1, Meridian Link, Meridian MAX, Meridian NAC, Meridian CCR, Meridian IVR, Meridian Terminal Emulator, MFA, Norstar, PowerTouch, SL-1, SL-100, SuperNode, Telesis, Unity.

Action Request System and AR System are trademarks of Remedy Corporation.

AMDEK is a trademark of Amdek Corporation.

ANSI is a trademark of the American National Standards Institute.

ClearCase is a registered trademark and ClearCase MultiSite is a trademark of Rational Software Corporation.

Continuus, continuus/CM, and Continuus/PT are trademarks of Continuus Software Corporation. CaseWare/CM, CaseWare/PT, CaseWare, ACCENT, and Amplify Control are registered trademarks of Continuus Software Corporation.

Courier is a trademark of Smith-Corona Corporation.

CT Connect, CT Media is a registered trademark of Dialogic.

Frame, FrameBuilder and FrameMaker are trademarks of Adobe Systems Incorporated.

Helvetica and Times are trademarks of Linotype AG or its subsidiaries.

InstallShield is a registered trademark of InstallShield Software Corporation.

Interleaf is a trademark of Interleaf, Inc.

Macintosh, Power Macintosh, and Apple are registered trademarks of Apple Computer, Inc. Mac OS is a trademark of Apple Computer, Inc.

Microsoft Windows, Microsoft Word, Microsoft Excel, PowerPoint, Microsoft Project, Microsoft File Extension, and MS-DOS are trademarks of Microsoft Corporation.

Novell is a trademark of Novell, Inc.

Olecera Chart is a trademark of KL Group Inc.

Portable Document Format is a trademark of Adobe Systems Incorporated.

PostScript is a trademark of Adobe Systems Incorporated.

SYBASE is a trademark of Sybase, Inc.

UNIX is a trademark of UNIX System Laboratories.

Versatility, Versatility Administrator, Versatility Call Blending, Versatility Campaign Plus, Versatility Insight, Versatility Predictive, Versatility Telesales / Teleservice are trademarks of Versatility Inc.

WinRunner, TSL and Context Sensitive are trademarks of Mercury Interactive Corporation.

© 2007 Nortel Networks Corporation

Page 3: CCMS 6.0 Security Templates

Approvals Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide iii

Approvals

Prepared By

Ronald Chan Date Senior Design Support Engineer, MA Design Support Enterprise Solutions, Multimedia Apps Support & Validation Nortel Networks Corporation

Reviewed and Approved By

James Chan Date Manager, MA Design Support Application R&D, Multimedia Apps Support & Validation Nortel Networks Corporation

David O’Connell Date Leader, CC Sustaining & Localization Application R&D, Multimedia Apps Support and Validation Nortel Networks Corporation

Page 4: CCMS 6.0 Security Templates

Revision history Nortel Proprietary

iv Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Revision history

Issue Number Issue Date

Type of Review Reason(s) for Issue

Author(s)

0.01 June 23, 2005

Draft copy

Initial draft for internal review

Ronald Chan

0.02 July 5, 2005

Draft copy

Section 3.1 Add CCMS 6.0 standalone server security template definitions

Ronald Chan

0.03 August 9, 2005

Draft copy

Section 2.3.2 Add Network Domain Deployment

Ronald Chan

0.04 September 21, 2005

Draft copy

Section 2.2 Changing template files location from the CC 6.0 DVD to the Meridian PEP Library web site

Section 2.2 Table 1 Remove CCO template

Section 2.3.1 Changing template files location from the CC 6.0 DVD to the Meridian PEP Library web site

Ronald Chan

0.05 July 7, 2006

Draft copy

Section 2.2 Update Table 1 to include CCMS 6.0 Replication server

Section 2.3.1 Add new Security Template Rollback section

Section 3.1 Add Contact Center Manager Replication server

Section 3.1 Update Table 3 with the latest CCMS 6.0 security template setting

Section 3.2 Update Table 4 with the latest CCMS 6.0 co-residency security template setting including CCT

Section 3.3 Update Table 5 with the latest CCMA 6.0 security template setting

Section 3.5 Add section and Table 6 with the CCT 6.0 standalone server security template setting

Ronald Chan

0.06 October 3, 2006

Draft copy

Section 2.5 Add section to outline the network environment requirements for the CC 6.0 servers with security template to operate with

Ronald Chan

Page 5: CCMS 6.0 Security Templates

Revision history Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide v

Issue Number Issue Date

Type of Review Reason(s) for Issue

Author(s)

1.00 October 20, 2006

Approved Copy

Section 2.2 Add note to clarify the set of security template is only applicable to Contact Center 6.0 only, and not applicable to any earlier Symposium portfolio releases.

Ronald Chan

1.01 October 15, 2008

Approved Copy

Section 2.2 Update Table 1 to add CCMM 6.0

Section 2.3.2 Update Table 2 to add CCMM 6.0

Section 3.5 Add section and Table 8 for CCMM 6.0 security template setting

Ronald Chan

1.02 October 29, 2008

Approved Copy

Section 2.2 Update Table 1 to add CCMS 6.0 Stratus

Section 2.3.2 Update Table 2 to add CCMS 6.0 Stratus

Section 3.6 Add section and Table 9 for CCMS 6.0 Stratus security template setting

Ronald Chan

Page 6: CCMS 6.0 Security Templates

Table of contents Nortel Proprietary

vi Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Table of contents 1 Introduction .........................................................................................................1

1.1 Purpose ...............................................................................................................................1 1.2 Scope...................................................................................................................................1 1.3 Intended audience ...............................................................................................................1

2 Contact Center 6.0 Security Templates.............................................................2 2.1 Contact Center 6.0 Security Template Baseline .................................................................2 2.2 Contact Center 6.0 Security Template Applicability ............................................................2 2.3 Contact Center 6.0 Security Templates Deployment ..........................................................3

2.3.1 Security Template Rollback....................................................................................4 2.3.2 Local Server Deployment .......................................................................................5 2.3.3 Network Domain Deployment.................................................................................9

2.4 Additional security settings..................................................................................................9 2.5 Network Environment Consideration.................................................................................10

3 Contact Center 6.0 Security Template Files ...................................................11 3.1 Contact Center Manager Server Security Template Definitions .......................................11 3.2 Contact Center Manager Server Co-residency Security Template Definitions .................35 3.3 Contact Center Manager Administration Security Template Definitions ...........................60 3.4 Communication Control Toolkit Security Template Definitions .........................................80 3.5 Contact Center Multimedia/Outbound Security Template Definitions.............................100 3.6 Contact Center Manager Server on Stratus Platform Security Template Definitions .....119

4 Glossary...........................................................................................................146

5 References.......................................................................................................148

Page 7: CCMS 6.0 Security Templates

List of tables Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide vii

List of tables Table 1 Contact Center 6.0 Security Template File Applicability with Contact Center Server......................3 Table 2 Contact Center 6.0 Security Template Rollback Files......................................................................4 Table 3 Contact Cetner 6.0 Security Template Additional Settings ............................................................10 Table 4 Contact Center Manager Server 6.0 Security Template Settings ..................................................11 Table 5 Contact Center Manager Server 6.0 Co-res Security Template Settings ......................................35 Table 6 Nortel Contact Center Manager Administration 6.0 Security Template Settings ...........................61 Table 7 Nortel Communication Control Toolkit 6.0 Security Template Settings .........................................80 Table 8 Contact Center Multimedia/Outbound 6.0 Security Template Setting .........................................100 Table 9 Contact Center Manager Server Stratus Security Template Settings..........................................120

Page 8: CCMS 6.0 Security Templates
Page 9: CCMS 6.0 Security Templates

Introduction Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 1

1 Introduction

1.1 Purpose

Security is a critical task for all organizations and it is always mandated to secure all networked servers by locking down the server operating system setting and services. Windows Server 2003 can be secured by applying a predefined security template either locally to the computer or through a network Group Policy Objects (GPO) instead of securing manually.

Nortel Contact Center 6.0 is providing a set of predefined Windows Server 2003 security templates that can be deployed quickly to secure the Contact Center 6.0 suite of application servers. The set of Contact Center 6.0 security templates is designed to be closely match the industry consensus security setting benchmark [1] published by the Center of Internet Security (CIS), and meeting the Contact Center 6.0 suite of application servers operation requirements.

This guide provides the detail definitions of the set of Contact Center 6.0 security templates and how to deploy the security templates to the Contact Center 6.0 suite of application servers.

1.2 Scope

This guide covers the set of security templates for Nortel Contact Center 6.0. It is not intended to be a comprehensive security guide either for the Nortel Contact Center 6.0 or the Windows Server 2003.

1.3 Intended audience

This guide is intended to be used by anyone wishing to secure the Contact Center 6.0 suite of application servers that are meeting the Contact Center 6.0 security template applicability requirements. It assumes that the reader is familiar with all security subjects and features in Windows Server 2003 and Microsoft network domain (Active Directory) environment.

Page 10: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

2 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

2 Contact Center 6.0 Security Templates

A set of security templates is available for the Contact Center 6.0 suite of application servers. You can apply the security template to its defined Contact Center 6.0 application server to secure the Windows Server 2003 and meeting the minimum security requirements for the Contact Center 6.0 application operation.

2.1 Contact Center 6.0 Security Template Baseline

All Contact Center 6.0 security templates are based on the consensus security benchmark document, Windows Server 2003 Operating System Legacy, Enterprise, and Specialized Security Benchmark Consensus Security Settings for Domain Member Servers [1], published by the Center of Internet Security (CIS) organization. This security benchmark reflects the content of the Consensus Baseline Security Settings document developed by the National Security Agency (NSA), the Defense Information Systems Agency (DISA), The National Institute and Technology (NIST), the General Service Administration (GSA), The SANS Institute, and the Center for Internet Security.

The Contact Center 6.0 security template settings are baseline with the Enterprise security level as defined in the consensus benchmark [1]. Settings in the Enterprise level are designed for servers operation in a managed environment where interoperability with legacy system is not required. It assumes that all operating systems within the enterprise are Windows 2000 or later. In addition, the security template settings are adjusted to meet the minimum security setting requirements for its specific Contact Center 6.0 application server as defined in its corresponding Nortel Contact Center 6.0 server security guide document [2].

2.2 Contact Center 6.0 Security Template Applicability

A set of the Contact Center 6.0 security template files is provided on the Meridian PEP Library web site. Table 1 lists the set of available template files and its corresponding applicable Contact Center 6.0 application server

Page 11: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 3

Table 1 Contact Center 6.0 Security Template File Applicability with Contact Center Server

Contact Center 6.0 Security Template File

Applicable Contact Center 6.0 Application Server

CCMS 6.0 Security Template.inf Contact Center Manager Server standalone server , Contact Center Manager Replication server, and Network Control Center server

CCMS 6.0 Cores Security Templt.inf Contact Center Manager Server co-residency server

CCMA 6.0 Security Template.inf Contact Center Manager Administration standalone server

CCT 6.0 Security Template.inf Communication Control Toolkit server

CCMM 6.0 Security Template.inf Contact Center Multimedia/Outbound server

CCMS 6.0 Stratus Security Temp.inf Contact Center Manager Server standalone server on Stratus platform, Contact Center Manager Replication server on Stratus platform, and Network Control Center server on Stratus platform

Note: The security template is applicable to Contact Center 6.0 only. It is not verified with its compatibility for any earlier Symposium portfolio products running on Windows Server 2003 platform. It is not applicable to any Symposium portfolio releases prior Contact Center 6.0.

The security template is designed to work with a typical server configuration and may not be compatible with some specific customer’s configuration. If customer is installing additional 3rd party software on the Contact Center 6.0 application server, customer must review and test the compatibility between the Contact Center 6.0 security template and the 3rd party software in a non-production environment. Customer may need to adjust the template if necessary.

2.3 Contact Center 6.0 Security Templates Deployment

The Contact Center 6.0 security template can be deployed either locally on the Contact Center 6.0 application server or as a group policy in an Active Directory OU where the Contact Center 6.0 application server is located. The Contact

Page 12: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

4 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Center 6.0 security template can be deployed either before or after the Contact Center 6.0 application is installed on the server.

2.3.1 Security Template Rollback

There are situation (like adding CCMA and CCT to a previously standalone CCMS server and convert it into a CCMS co-residency server) that one may require to rollback the originally applied Contact Center 6.0 security template and reapply a new one that is appropriate with the new Contact Center 6.0 application server configuration. A set of Contact Center 6.0 default rollback templates for the corresponding Contact Center 6.0 security templates are provided. These default rollback templates will rollback the security setting (excluding permission setting in registries and files) from the applied security template back to the default Windows Server 2003 (with SP1) setting. Table 2 lists the set of available rollback template files and its corresponding applicable Contact Center 6.0 application server.

Table 2 Contact Center 6.0 Security Template Rollback Files

Contact Center 6.0 Security Template Rollback File

Applicable Contact Center 6.0 Application Server

CCMS 6.0 Security Templt Rollb.inf Contact Center Manager Server standalone server, Contact Center Manager Replication server, and Network Control Center server

CCMS 6.0 Cores Sec Templt Rollb.inf Contact Center Manager Server co-residency server

CCMA 6.0 Security Templt Rollb.inf Contact Center Manager Administration standalone server

CCT 6.0 Security Templt Rollb.inf Communication Control Toolkit server

CCMM 6.0 Security Templ Roll.inf Contact Center Multimedia/Outbound server

CCMS 6.0 Stratus Sec Tmp Rollbk.inf Contact Center Manager Server standalone server on Stratus platform, Contact Center Manager Replication server on Stratus platform, and Network Control Center server on Stratus platform

Page 13: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 5

If Windows Server 2003 configuration is different from its default installed setting before applying the Contact Center 6.0 security template, the default rollback template may not restore the configuration to its customized configuration. It is Nortel recommendation that you must create an appropriate rollback template on your Contact Center 6.0 application server before deploying the Contact Center 6.0 security template. The rollback template can be generated by issuing the “secedit /GenerateRollback /CFG <CC 6.0 Security Template.inf> /RBK <Rollback Template.inf>” (e.g., secedit /GenerateRollback /CFG “C:\CCMS 6.0 Security Template.inf” /RBK C:\rollback.inf) command in a command line prompt windows.

2.3.2 Local Server Deployment

To deploy the Contact Center 6.0 Security template locally on a Contact Center 6.0 application server, one must select the applicable security template for the Contact Center 6.0 application server and download the selected template from the Meridian PEP Library web site to the server local disk drive. The security template can then be imported and configured using the Microsoft Security Configuration and Analysis utility.

The following steps can be used to deploy the Contact Center 6.0 security template using the Security Configuration and Analysis (you must add the Security Configuration and Analysis snap-in to the Microsoft Management Console):

1) Logon to the server with an administrative account.

2) Open the management console that is having the Security Configuration and Analysis snap-in.

Page 14: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

6 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

3) Right click the Security Configuration and Analysis scope item and click Open Database. Enter a new database name (e.g., CCMA 6.0 Security Template) in the File Name field of the Open Data dialog windows, and then press the Open button.

4) On the Import Template dialog windows, browse and select the Contact Center 6.0 security template file downloaded from the Meridian PEP Library Web site, and then press the Open button.

Page 15: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 7

5) Right click the Security Configuration and Analysis scope item, and click the Analyze Computer Now to analyze the security configuration with the imported Contact Center 6.0 security template and the current server configuration.

6) On the Perform Analysis dialog windows, select the default log file path (e.g., C:\Documents and Setttings\Administrator\My Documents\Security\Logs\CCMA 6.0 Security Template.log) or select the log file path of your choice, press the OK button to perform the analysis.

Page 16: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

8 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

7) Open the security analysis log file with a text editor and review any mismatch item that may not meet your server requirement. Adjust the security template if necessary.

8) Right click the Security Configuration and Analysis scope item from the Security Configuration and Analysis snap-in management console. Click Configure Computer Now to configure the server security configuration with the imported Contact Center 6.0 security template.

9) On the Configure System dialog windows, select the default log file path (e.g., C:\Documents and Setttings\Administrator\My Documents\Security\Logs\CCMA 6.0 Security Template.log) or select the log file path of your choice, press the OK button to configure the computer.

Page 17: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 9

10) Reboot the server to activate the new security policy and configuration.

2.3.3 Network Domain Deployment

The Contact Center 6.0 security templates can be deployed in a network domain environment by importing the template into a group policy object of an OU where the Contact Center 6.0 server is a member. To import a security template:

1) Open Group Policy Management Console (GPMC)

2) In the console tree, expand the domain or OU that you want to import the security template. Right-click the Group Policy object that you want to edit, and then click Edit.

3) In the Group Policy Object Editor console tree, click Computer Configuration, click Windows Settings, right-click Security Setting, and then select Import Policy.

4) Click the Contact Center 6.0 security template that you want to import, then click Open.

2.4 Additional security settings

Due to some security setting are unique in individual computer, these security settings cannot be set through a common security template and must be set locally on the computer. Nortel recommends the following additional security settings be set manually on each Contact Center 6.0 application server after the security template has been deployed.

Page 18: CCMS 6.0 Security Templates

Contact Center 6.0 Security Templates Nortel Proprietary

10 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Table 3 Contact Cetner 6.0 Security Template Additional Settings

Security Setting Additional settings

User Right Assignments

Deny access to this computer from the network (minimum)

Built-in Administrator, Support_388945a0, Guest

Deny logon as a batch job Support_388945a0, Guest

Deny logon through Terminal Service (minimum) Support_388945a0, Guest

Security Options

Accounts: Rename Administrator Account <non-standard>

Accounts: Rename Guest Account <non-standard>

Interactive Logon: Message Text for Users Attempting to Log On

<Custom, or DoJ approved>

Interactive Logon: Message Title for Users Attempting to Log On

<Custom, or DoJ approved>

2.5 Network Environment Consideration

The Contact Center 6.0 security template settings are baseline with the Enterprise security level as defined in the consensus benchmark [1]. Settings in the Enterprise level are designed for servers operation in a managed environment where interoperability with legacy system is not required. It assumes that all operating systems within the enterprise network are Windows 2000 or later.

Contact Center 6.0 security template is following the consensus benchmark [1] recommendation to enable the security policy “Microsoft network client: Digitally sign communications (always)” to digitally sign all SMB communications. If a Contact Center 6.0 application sever that is having the security template applied and need to map a remote network share on a remote PC, the connecting remote PC muse have the corresponding security policy to be set by enabling either the “Microsoft network server: Digitally sign communications (always)” or “Micrsoft network server: Digitally sign communication (if client agrees)”.

Page 19: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 11

3 Contact Center 6.0 Security Template Files

3.1 Contact Center Manager Server Security Template Definitions

Table 4 lists the security template setting defined for the Contact Center Manager Server in a standalone server configuration, Contact Center Manager Replication server, and Network Control Center server.

Table 4 Contact Center Manager Server 6.0 Security Template Settings

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8

Password must meet complexity requirements Enabled

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Maximum tolerance for computer clock synchronization <Not defined>

Page 20: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

12 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Audit object access Success, Failure

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Deny access to this computer from the network ANONYMOUS LOGON, Guests

Deny log on as a batch job Guests

Page 21: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 13

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Generate security audits <Not defined>

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <None>

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Page 22: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

14 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Audit: Audit the access of global system objects <Not defined>

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when Enabled

Page 23: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 15

possible)

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Interactive logon: Display user information when the session is locked

<Not defined>

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications (always)

<Not defined>

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Page 24: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

16 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock applications

20000 (recommended)

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers

Enabled

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

Page 25: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 17

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

MSS: The time in seconds before the screen saver grace period expires

0

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIndex

System\CurrentControlSet\Control\Terminal Server\UserConfig

Page 26: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

18 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disable

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user keys stored on computer

User must enter a password each time they use a key

System cryptography: User FIPS compliant algorithms for <Not defined>

Page 27: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 19

encryption, hashing, and signing

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal system objects

Enabled

System settings: Option subsystems <None>

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Application Experience Lookup Service

(AeLookupSvc)

<Not defined>

Page 28: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

20 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(applicable to Windows Server 2003 SP1)

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management

(AppMgmt)

<Not defined>

Client Service for Netware

(NWCWorkstation)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

ASP.NET State Service

(aspnet_state)

<Not defined>

Automatic Updates

(Wuauserv)

<Not defined>

Background Intelligent Transfer Service

(BITS)

<Not defined>

CC License Manager

(CC_LM)

(Built-in CC 6.0 service)

<Not defined>

CC Replication Service

(REP_Service)

(Built-in CCMS service

<Not defined>

CCMS ASM_Service

(ASM_Service)

(Built-in CCMS Service)

<Not defined>

CCMS Audit_Service

(AUDIT_Service)

(Built-in CCMS service)

<Not defined>

CCMS Control Service

(CCMS_MasterService)

(Built-in CCMS service)

<Not defined>

Page 29: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 21

CCMS DBNotifier_Service

(DBNotifier_Service)

(Built-in CCMS service)

<Not defined>

CCMS EB_Service

(EB_Service)

(Built-in CCMS service)

<Not defined>

CCMS ES_Service

(ES_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDC_Service

(HDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDM_Service

(HDM_Service)

(Built-in CCMS service)

<Not defined>

CCMS Host Application Integration

(Host Application Integration)

(Built-in CCMS service)

<Not defined>

CCMS IS_Service

(IS_Service)

(Built-in CCMS service)

<Not defined>

CCMS MAS Backup/Restore

(nbbkp)

(Built-in CCMS service)

<Not defined>

CCMS MAS Configuration Manager

(nbcfg)

(Built-in CCMS service)

<Not defined>

CCMS MAS Event Scheduler <Not defined>

Page 30: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

22 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(nbsch)

(Built-in CCMS service)

CCMS MAS Fault Manager

(nbflt)

(Built-in CCMS service)

<Not defined>

CCMS MAS LinkHandler Port #2

(nbalh)

(Built-in CCMS service)

<Not defined>

CCMS MAS OM Server

(nboms)

(Built-in CCMS service)

<Not defined>

CCMS MAS Security

(nbss)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Daemon

(nbsm_dae)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Manager

(nbsm)

(Built-in CCMS service)

<Not defined>

CCMS MAS Time Service

(nbts)

(Built-in CCMS service)

<Not defined>

CCMS MLSM_Service

(MLSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBMSM_Service

(CCMS_NBMSM_Service)

<Not defined>

Page 31: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 23

(Built-in CCMS service)

CCMS NBNM_Service

(NBNM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBTSM_Service

(NBTSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NCCOAM_Service

(NCCOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NDLOAM_Service

(NDLOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NIMSM_Service

(CCMS_NIMSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NINCCAudit_Service

(NINCCAudit_Service)

(Built-in CCMS service)

<Not defined>

CCMS NITSM_Service

(NITSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAM_Service

(OAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAMCMF_Service

(CCMS_OAM_CMF_Service)

(Built-in CCMS service)

<Not defined>

Page 32: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

24 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

CCMS RDC_Service

(RDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS RSM_Service

(RSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS SDMCA_Service

(SDMCA_Service)

(Built-in CCMS service)

<Not defined>

CCMS SDP_Service

(SDP_Service)

(Built-in CCMS Service)

<Not defined>

CCMS SIP_Service

(CCMS_SIP_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFA_Service

(TFA_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFABRIDGE_Service

(TFABRIDGE_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFE Bridge Connector

(TfeBridgeConnector)

(Built-in CCMS service)

<Not defined>

CCMS TFE_Service

(TFE_Service)

(Built-in CCMS service)

<Not defined>

CCMS UNE_Service <Not defined>

Page 33: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 25

(CCMS_UNE_Service)

(Built-in CCMS service)

CCMS VSM_Service

(VSM_Service)

(Built-in CCMS service)

<Not defined>

ClipBook

(ClipSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

Page 34: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

26 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

DNS Client

(Dnscache)

<Not defined>

Error Reporting Services

(ERSvc)

<Not defined>

Event Log

(Eventlog)

<Not defined>

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service Disabled

Page 35: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 27

(Cisvc) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager

(Built-in InstallShield service for CC installation)

<Not defined>

Intersite Messaging

(IsmServ)

<Not defined>

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging Service

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

(Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network Connections Manual

Page 36: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

28 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Netman) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM

(NetDDEdsdm)

<Not defined>

Network Location Awareness

(NLA)

<Not defined>

Network Provisioning Service

(xmlprov)

(applicable to Windows Server 2003 SP1)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service

(WmdmPmSN)

<Not defined>

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Protect Storage <Not defined>

Page 37: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 29

(ProtectedStorage)

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

<Not defined>

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator

(RpcLocator)

<Not defined>

Remote Registry

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Server Monitor

(Appmon)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control,

Page 38: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

30 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Routing and Remote Access

(RemoteAccess)

<Not defined>

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

(ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP)

(SMTPSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service

(SNMPTRAP)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

Sybase BCKServer_<server name>_BS

(SYBBCK_<server name>_BS)

(Built-in CCMS Sybase service)

<Not defined>

Page 39: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 31

Sybase MONServer_<server name>_MS

(SYBMON_<server name>_MS)

(Built-in CCMS Sybase service)

<Not defined>

Sybase SQLServer_<server name>

(SYBSQL_<server name>)

(Built-in CCMS Sybase service)

<Not defined>

Sybase XPServer_<server name>_XP

(SYBXPS_<server name>_XP)

(Built-in CCMS Sybase service)

<Not defined>

Sybase ASE Protect Service

(SybProtect)

(Built-in CCMS Sybase service)

<Not defined>

System Event Notification

(SENS)

<Not defined>

TAO NT Naming Service

(TAO_NT_Naming_Service)

(Built-in CCMS TAO service)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper Service

(LMHosts)

<Not defined>

Telephony

(TapiSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Telnet

(TlntSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Services

(TermService)

<Not defined>

Page 40: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

32 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon

(tftpd)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes

(Themes)

<Not defined>

Uninterruptible Power Supply

(UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

(VSS)

<Not defined>

Web Element Manager

(elementmgr)

<Not defined>

WebClient

(WebClient)

<Not defined>

Windows Audio

(AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS)

(SharedAccess)

<Not defined>

Windows Image Acquisition (WIA)

(StiSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Page 41: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 33

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time

(W32Time)

<Not defined>

Windows User Mode Driver Framework

(UMWdf)

(applicable to Windows Server 2003 SP1)

<Not defined>

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

World Wide Web Publishing Service

(W3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full

Page 42: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

34 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full

Page 43: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 35

Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

3.2 Contact Center Manager Server Co-residency Security Template Definitions

Table 5 lists the security template setting defined for the Contact Center Manager Server 6.0 Co-residency server (co-residency with CCMS, CCMA, and CCT).

Table 5 Contact Center Manager Server 6.0 Co-res Security Template Settings

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Page 44: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

36 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8 characters

Password must meet complexity requirements Enabled

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Maximum tolerance for computer clock synchronization <Not defined>

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Audit object access Success, Failure

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Page 45: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 37

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Deny access to this computer from the network ANONYMOUS LOGON, Guests

Deny log on as a batch job Guests

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Generate security audits <Not defined>

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <Not defined>

Page 46: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

38 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Audit: Audit the access of global system objects <Not defined>

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Page 47: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 39

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when possible)

Enabled

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Interactive logon: Display user information when the session is locked

<Not defined>

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log <Not defined>

Page 48: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

40 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

on (Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications (always)

<Not defined>

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock applications

20000 (recommended)

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

Page 49: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 41

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers

Enabled

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

MSS: The time in seconds before the screen saver grace period expires

0

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Page 50: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

42 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIndex

System\CurrentControlSet\Control\Terminal Server\UserConfig

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Page 51: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 43

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disable

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user keys stored on computer

User must enter a password each time they use a key

System cryptography: User FIPS compliant algorithms for encryption, hashing, and signing

<Not defined>

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal system objects

Enabled

System settings: Option subsystems <None>

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Page 52: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

44 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

ACDPROXY Service <Not defined>

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Application Experience Lookup Service

(AeLookupSvc)

(applicable to Windows Server 2003 SP1)

<Not defined>

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management

(AppMgmt)

<Not defined>

Client Service for Netware

(NWCWorkstation)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

ASP.NET State Service

(aspnet_state)

<Not defined>

Automatic Updates <Not defined>

Page 53: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 45

(Wuauserv)

Background Intelligent Transfer Service

(BITS)

<Not defined>

CCMA ICEEmHlpService

(Built-in CCMA service)

<Not defined>

CCMA IceRTDService

(Built-in CCMA service)

<Not defined>

CCMA LMService

(Built-in CCMA service)

<Not defined>

CC License Manager

(CC_LM)

(Built-in CC 6.0 service)

<Not defined>

CC Replication Service

(REP_Service)

(Built-in CCMS service

<Not defined>

CCMS ASM_Service

(ASM_Service)

(Built-in CCMS Service)

<Not defined>

CCMS Audit_Service

(AUDIT_Service)

(Built-in CCMS service)

<Not defined>

CCMS Control Service

(CCMS_MasterService)

(Built-in CCMS service)

<Not defined>

CCMS DBNotifier_Service

(DBNotifier_Service)

(Built-in CCMS service)

<Not defined>

CCMS EB_Service <Not defined>

Page 54: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

46 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(EB_Service)

(Built-in CCMS service)

CCMS ES_Service

(ES_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDC_Service

(HDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDM_Service

(HDM_Service)

(Built-in CCMS service)

<Not defined>

CCMS Host Application Integration

(Host Application Integration)

(Built-in CCMS service)

<Not defined>

CCMS IS_Service

(IS_Service)

(Built-in CCMS service)

<Not defined>

CCMS MAS Backup/Restore

(nbbkp)

(Built-in CCMS service)

<Not defined>

CCMS MAS Configuration Manager

(nbcfg)

(Built-in CCMS service)

<Not defined>

CCMS MAS Event Scheduler

(nbsch)

(Built-in CCMS service)

<Not defined>

CCMS MAS Fault Manager

(nbflt)

<Not defined>

Page 55: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 47

(Built-in CCMS service)

CCMS MAS LinkHandler Port #2

(nbalh)

(Built-in CCMS service)

<Not defined>

CCMS MAS OM Server

(nboms)

(Built-in CCMS service)

<Not defined>

CCMS MAS Security

(nbss)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Daemon

(nbsm_dae)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Manager

(nbsm)

(Built-in CCMS service)

<Not defined>

CCMS MAS Time Service

(nbts)

(Built-in CCMS service)

<Not defined>

CCMS MLSM_Service

(MLSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBMSM_Service

(CCMS_NBMSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBNM_Service

(NBNM_Service)

(Built-in CCMS service)

<Not defined>

Page 56: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

48 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

CCMS NBTSM_Service

(NBTSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NCCOAM_Service

(NCCOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NDLOAM_Service

(NDLOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NIMSM_Service

(CCMS_NIMSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NINCCAudit_Service

(NINCCAudit_Service)

(Built-in CCMS service)

<Not defined>

CCMS NITSM_Service

(NITSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAM_Service

(OAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAMCMF_Service

(CCMS_OAM_CMF_Service)

(Built-in CCMS service)

<Not defined>

CCMS RDC_Service

(RDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS RSM_Service <Not defined>

Page 57: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 49

(RSM_Service)

(Built-in CCMS service)

CCMS SDMCA_Service

(SDMCA_Service)

(Built-in CCMS service)

<Not defined>

CCMS SDP_Service

(SDP_Service)

(Built-in CCMS Service)

<Not defined>

CCMS SIP_Service

(CCMS_SIP_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFA_Service

(TFA_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFABRIDGE_Service

(TFABRIDGE_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFE Bridge Connector

(TfeBridgeConnector)

(Built-in CCMS service)

<Not defined>

CCMS TFE_Service

(TFE_Service)

(Built-in CCMS service)

<Not defined>

CCMS UNE_Service

(CCMS_UNE_Service)

(Built-in CCMS service)

<Not defined>

CCMS VSM_Service

(VSM_Service)

<Not defined>

Page 58: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

50 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Built-in CCMS service)

ClipBook

(ClipSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

Crystal Report Application Server

(built-in CCMA Crystal Report service)

<Not defined>

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

DNS Client

(Dsncache)

<Not defined>

Page 59: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 51

Error Reporting Services

(ERSvc)

<Not defined>

Event Log

(Eventlog)

<Not defined>

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

<Not defined>

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

<Not defined>

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service

(Cisvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager <Not defined>

Page 60: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

52 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Built-in InstallShield service for CC installation)

Intersite Messaging

(IsmServ)

<Not defined>

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

(Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

MSSQL$NNCCTDB

(Built-in CCT SQL server)

<Not defined>

MSSQLServerADHelper

(Built-in CCT SQL service)

<Not defined>

NCCT Data Access Layer

(Built-in CCT service)

<Not defined>

NCCT Server

(Built-in CCT service)

<Not defined>

Page 61: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 53

NCCT TAPI Connector Service

(Built-in CCT service)

<Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network Connections

(Netman)

Manual

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM

(NetDDEdsdm)

<Not defined>

Network Location Awareness

(NLA)

<Not defined>

Network Provisioning Service

(xmlprov)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service <Not defined>

Page 62: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

54 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(WmdmPmSN)

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Protect Storage

(ProtectedStorage)

<Not defined>

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator

(RpcLocator)

<Not defined>

Remote Registry

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Page 63: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 55

Remote Server Monitor

(APPMON)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Routing and Remote Access

(RemoteAccess)

<Not defined>

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

(ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP)

(SMTPSVC)

<Not defined>

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service Disabled

Page 64: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

56 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(SNMPTRAP) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

SQLAgent$NNCCTDB

(Built-in CCT SQL Agent service)

<Not defined>

Sybase BCKServer_<server name>_BS

(SYBBCK_<server name>_BS)

(Built-in CCMS Sybase service)

<Not defined>

Sybase MONServer_<server name>_MS

(SYBMON_<server name>_MS)

(Built-in CCMS Sybase service)

<Not defined>

Sybase SQLServer_<server name>

(SYBSQL_<server name>)

(Built-in CCMS Sybase service)

<Not defined>

Sybase XPServer_<server name>_XP

(SYBXPS_<server name>_XP)

(Built-in CCMS Sybase service)

<Not defined>

Sybase ASE Protect Service

(SybProtect)

(Built-in CCMS Sybase service)

<Not defined>

SymposiumWC

(Built-in CCMA ADAM service)

<Not defined>

System Event Notification

(SENS)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper

(LMHost)

<Not defined>

Page 65: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 57

Telephony

(TapiSrv)

<Not defined>

Telnet

(TlnetSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Service

(TermService)

<Not defined>

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon

(tftpd)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes

(Themes)

<Not defined>

Uninterruptible Power Supply

UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

(VSS)

<Not defined>

Web Element Manager

(elementmgr)

<Not defined>

WebClient

(WebClient)

<Not defined>

Windows Audio

(AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS) <Not defined>

Page 66: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

58 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(SharedAccess)

Windows Image Acquisition (WIA)

(SuSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time

(W32Time)

<Not defined>

Windows User Mode Driver Framework

(UMWdf)

<Not defined>

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

World Wide Web Publishing Service

(W3SVC)

<Not defined>

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

Page 67: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 59

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control,

Page 68: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

60 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

3.3 Contact Center Manager Administration Security Template Definitions

Table 6 lists the security template setting defined for the Nortel Contact Center Manager Administration 6.0 server.

Page 69: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 61

Table 6 Nortel Contact Center Manager Administration 6.0 Security Template Settings

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8 characters

Password must meet complexity requirements Enabled

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Maximum tolerance for computer clock synchronization <Not defined>

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Page 70: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

62 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Audit object access Success, Failure

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Deny access to this computer from the network ANONYMOUS LOGON, Guests

Deny log on as a batch job Guests

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Page 71: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 63

Generate security audits <Not defined>

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <Not defined>

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Page 72: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

64 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Audit: Audit the access of global system objects <Not defined>

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when possible)

Enabled

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Page 73: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 65

Interactive logon: Display user information when the session is locked

<Not defined>

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications (always)

<Not defined>

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

Page 74: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

66 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock applications

20000 (recommended)

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers

Enabled

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

Page 75: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 67

MSS: The time in seconds before the screen saver grace period expires

0

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIndex

System\CurrentControlSet\Control\Terminal Server\UserConfig

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Page 76: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

68 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disable

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user keys stored on computer

User must enter a password each time they use a key

System cryptography: User FIPS compliant algorithms for encryption, hashing, and signing

<Not defined>

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal Enabled

Page 77: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 69

system objects

System settings: Option subsystems <None>

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Application Experience Lookup Service

(AeLookupSvc)

(applicable to Windows Server 2003 SP1)

<Not defined>

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management <Not defined>

Page 78: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

70 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(AppMgmt)

Client Service for Netware

(NWCWorkstation)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

ASP.NET State Service

(aspnet_state)

<Not defined>

Automatic Updates

(Wuauserv)

<Not defined>

Background Intelligent Transfer Service

(BITS)

<Not defined>

CCMA ICEEmHlpService

(Built-in CCMA service)

<Not defined>

CCMA IceRTDService

(Built-in CCMA service)

<Not defined>

CCMA LMService

(Built-in CCMA service)

<Not defined>

ClipBook

(ClipSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

Crystal Report Application Server

(built-in CCMA Crystal Report service)

<Not defined>

Page 79: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 71

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

DNS Client

(Dnscache)

<Not defined>

Error Reporting Services

(ERSvc)

<Not defined>

Event Log

(Eventlog)

<Not defined>

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control,

Page 80: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

72 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

<Not defined>

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

<Not defined>

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service

(Cisvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager

(Built-in InstallShield service for CC installation)

<Not defined>

Intersite Messaging

(IsmServ)

<Not defined>

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Page 81: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 73

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network Connections

(Netman)

Manual

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM

(NetDDEdsdm)

<Not defined>

Network Location Awareness (NLA)

(NLA)

<Not defined>

Network Provisioning Service

(xmlprov)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Page 82: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

74 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service

(WmdmPmSN)

<Not defined>

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Protect Storage

(ProtectStorage)

<Not defined>

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator <Not defined>

Page 83: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 75

(PrcLocator)

Remote Registry

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Server Monitor

(APPMON)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Routing and Remote Access

(RemoteAccess)

<Not defined>

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP) <Not defined>

Page 84: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

76 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(SMTPSVC)

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service

(SNMPTRAP)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

SymposiumWC

(Built-in CCMA ADAM service)

<Not defined>

System Event Notification

(SENS)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper

(LMHost)

<Not defined>

Telephony

(TapiSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Telnet

(TlntSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Service

(TermService)

<Not defined>

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon Disabled

Page 85: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 77

(tftpd) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes

(Themes)

<Not defined>

Uninterruptible Power Supply

(UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

VSS)

<Not defined>

Web Element Manager

(elementmgr)

<Not defined>

WebClient

(WebClient)

<Not defined>

Windows Audio

AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS)

(SharedAccess)

<Not defined>

Windows Image Acquisition (WIA)

(SuSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time <Not defined>

Page 86: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

78 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(W32Time)

Windows User Mode Driver Framework

(UMWdf)

<Not defined>

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

World Wide Web Publishing Service

(W3SVC)

<Not defined>

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full

Page 87: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 79

Control

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

Page 88: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

80 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

3.4 Communication Control Toolkit Security Template Definitions

Table 7 lists the security template setting defined for the Nortel Communication Control Toolkit 6.0 server.

Table 7 Nortel Communication Control Toolkit 6.0 Security Template Settings

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8

Password must meet complexity requirements Enabled

Page 89: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 81

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Maximum tolerance for computer clock synchronization <Not defined>

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Audit object access Success, Failure

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Page 90: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

82 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Deny access to this computer from the network ANONYMOUS LOGON, Guests

Deny log on as a batch job Guests

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Generate security audits <Not defined>

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <None>

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Page 91: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 83

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Audit: Audit the access of global system objects <Not defined>

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Page 92: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

84 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when possible)

Enabled

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Interactive logon: Display user information when the session is locked

<Not defined>

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Page 93: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 85

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications (always)

<Not defined>

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock applications

20000 (recommended)

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer Enabled

Page 94: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

86 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

to ignore NetBIOS name release requests except from WINS servers

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

MSS: The time in seconds before the screen saver grace period expires

0

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

Page 95: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 87

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIndex

System\CurrentControlSet\Control\Terminal Server\UserConfig

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Page 96: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

88 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disable

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user keys stored on computer

User must enter a password each time they use a key

System cryptography: User FIPS compliant algorithms for encryption, hashing, and signing

<Not defined>

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal system objects

Enabled

System settings: Option subsystems <None>

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Page 97: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 89

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

ACDPROXY Service <Not defined>

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Application Experience Lookup Service

(AeLookupSvc)

(applicable to Windows Server 2003 SP1)

<Not defined>

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management

(AppMgmt)

<Not defined>

CC License Manager

(applicable if CC License Manager is installed on the CCT server)

<Not defined>

Client Service for Netware

(NWCWorkstation)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Automatic Updates

(Wuauserv)

<Not defined>

Background Intelligent Transfer Service

(BITS)

<Not defined>

Page 98: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

90 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

ClipBook

(ClipSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

DNS Client

(Dnscache)

<Not defined>

Error Reporting Services

(ERSvc)

<Not defined>

Event Log <Not defined>

Page 99: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 91

(Eventlog)

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service

(Cisvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager

(Built-in InstallShield service for CC installation)

<Not defined>

Intersite Messaging <Not defined>

Page 100: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

92 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(IsmServ)

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging Service

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

(Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

MSSQL$NNCCTDB <Not defined>

MSSQLServerADHelper <Not defined>

NCCT Data Access Layer <Not defined>

NCCT Logging Service <Not defined>

NCCT Server <Not defined>

NCCT TAPI Connector Service <Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control,

Page 101: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 93

System=Full Control, Interactive=Read)

Network Connections

(Netman)

Manual

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM

(NetDDEdsdm)

<Not defined>

Network Location Awareness

(NLA)

<Not defined>

Network Provisioning Service

(applicable to Windows Server 2003 SP1)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service

(WmdmPmSN)

<Not defined>

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Page 102: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

94 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Protect Storage

(ProtectedStorage)

<Not defined>

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator

(RpcLocator)

<Not defined>

Remote Registry Service

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Server Monitor

(Appmon)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Page 103: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 95

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Routing and Remote Access

(RemoteAccess)

<Not defined>

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

(ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP)

(SMTPSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service

(SNMPTRAP)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

SQLAgent$NNCCTDB <Not defined>

Page 104: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

96 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System Event Notification

(SENS)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper Service

(LMHosts)

<Not defined>

Telephony

(TapiSrv)

<Not defined>

Telnet

(TlntSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Services

(TermService)

<Not defined>

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon

(tftpd)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes

(Themes)

<Not defined>

Uninterruptible Power Supply

(UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

(VSS)

<Not defined>

Web Element Manager <Not defined>

Page 105: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 97

(elementmgr)

WebClient

(WebClient)

<Not defined>

Windows Audio

(AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS)

(SharedAccess)

<Not defined>

Windows Image Acquisition (WIA)

(StiSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time

(W32Time)

<Not defined>

Windows User Mode Driver Framework

(UMWdf)

(applicable to Windows Server 2003 SP1)

<Not defined>

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

Page 106: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

98 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

World Wide Web Publishing Service

(W3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

Page 107: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 99

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

Page 108: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

100 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

3.5 Contact Center Multimedia/Outbound Security Template Definitions

Table 8 lists the security template setting defined for the Nortel Contact Center Multimedia/Outbound 6.0 server.

Table 8 Contact Center Multimedia/Outbound 6.0 Security Template Setting

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8 characters

Password must meet complexity requirements Enabled

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Page 109: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 101

Maximum tolerance for computer clock synchronization <Not defined>

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Audit object access Success, Failure

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Page 110: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

102 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Deny access to this computer from the network ANONYMOUS LOGON

Deny log on as a batch job Guests

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Generate security audits <Not defined>

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <Not defined>

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Page 111: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 103

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Audit: Audit the access of global system objects <Not defined>

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Page 112: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

104 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when possible)

Enabled

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Interactive logon: Display user information when the session is locked

<Not defined>

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications <Not defined>

Page 113: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 105

(always)

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock applications

20000 (recommended)

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers

Enabled

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

Page 114: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

106 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

MSS: The time in seconds before the screen saver grace period expires

0

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIn

Page 115: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 107

dex

System\CurrentControlSet\Control\Terminal Server\UserConfig

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disabled

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user User must enter a password each time they

Page 116: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

108 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

keys stored on computer use a key

System cryptography: User FIPS compliant algorithms for encryption, hashing, and signing

<Not defined>

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal system objects

Enabled

System settings: Option subsystems <None>

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Page 117: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 109

Application Experience Lookup Service

(AeLookupSvc)

(applicable to Windows Server 2003 SP1)

<Not defined>

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management

(AppMgmt)

<Not defined>

Client Service for Netware

(NWCWorkstation)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

ASP.NET State Service

(aspnet_state)

<Not defined>

Automatic Updates

(Wuauserv)

<Not defined>

Background Intelligent Transfer Service

(BITS)

<Not defined>

Cache Controller for Nortel

(Built-in Cache service for CCMM)

<Not defined>

CCMM Email Manager Service

(Built-in CCMM service)

<Not defined>

CCMM License Service

(Built-in CCMM service)

<Not defined>

CCMM Manager Client Service

(Built-in CCMM service)

<Not defined>

CCMM OAM Service

(Built-in CCMM service)

<Not defined>

CCMM Outbound Scheduler Service

(Built-in CCMM service)

<Not defined>

CCMM Starter Service <Not defined>

Page 118: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

110 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Built-in CCMM service)

ClipBook

(ClipSrv)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

DNS Client

(Dnscache)

<Not defined>

Error Reporting Services

(ERSvc)

<Not defined>

Page 119: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 111

Event Log

(Eventlog)

<Not defined>

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

<Not defined>

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

<Not defined>

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service

(Cisvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager

(Built-in InstallShield service for CC installation)

<Not defined>

Intersite Messaging <Not defined>

Page 120: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

112 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(IsmServ)

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network Connections

(Netman)

Manual

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM <Not defined>

Page 121: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 113

(NetDDEdsdm)

Network Location Awareness (NLA)

(NLA)

<Not defined>

Network Provisioning Service

(xmlprov)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service

(WmdmPmSN)

<Not defined>

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Protect Storage

(ProtectStorage)

<Not defined>

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

Disabled

(Permissions: Administrators=Full Control,

Page 122: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

114 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System=Full Control, Interactive=Read)

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator

(PrcLocator)

<Not defined>

Remote Registry

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Server Monitor

(APPMON)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Page 123: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 115

Routing and Remote Access

(RemoteAccess)

<Not defined>

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP)

(SMTPSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service

(SNMPTRAP)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

System Event Notification

(SENS)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper

(LMHost)

<Not defined>

Telephony Disabled

Page 124: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

116 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(TapiSrv) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Telnet

(TlntSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Service

(TermService)

<Not defined>

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon

(tftpd)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes

(Themes)

<Not defined>

Uninterruptible Power Supply

(UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

VSS)

<Not defined>

Web Element Manager

(elementmgr)

<Not defined>

WebClient

(WebClient)

<Not defined>

Windows Audio

AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS)

(SharedAccess)

<Not defined>

Page 125: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 117

Windows Image Acquisition (WIA)

(SuSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time

(W32Time)

<Not defined>

Windows User Mode Driver Framework

(UMWdf)

<Not defined>

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

World Wide Web Publishing Service

(W3SVC)

<Not defined>

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

Page 126: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

118 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control,

Page 127: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 119

INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

3.6 Contact Center Manager Server on Stratus Platform Security Template Definitions

Table 9 lists the security template setting defined for the Contact Center Manager Server in a standalone server configuration, Contact Center Manager Replication server, or Network Control Center server running on the Stratus platform

Page 128: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

120 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Table 9 Contact Center Manager Server Stratus Security Template Settings

Security Setting Items Setting

Account Policies

Password Policy

Enforce password history 24 passwords remembered

Maximum password age 90 days

Minimum password age 1 days

Minimum password length 8

Password must meet complexity requirements Enabled

Store passwords using reversible encryption Disabled

Account Lockout Policy

Account lockout duration 15 minutes

Account lockout threshold 15 invalid logon attempts

Reset account lockout counter after 15 minutes

Kerberos Policy

Enforce user logon restrictions <Not defined>

Maximum lifetime for service ticket <Not defined>

Maximum lifetime for user ticket <Not defined>

Maximum lifetime for user ticket renewal <Not defined>

Maximum tolerance for computer clock synchronization <Not defined>

Local Policies

Audit Policy

Audit account logon events Success, Failure

Audit account management Success, Failure

Audit directory service access <Not defined>

Audit logon events Success, Failure

Audit object access Success, Failure

Page 129: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 121

Audit policy change Success

Audit privilege use <Not defined>

Audit process tracking <Not defined>

Audit system events Success

User Rights Assignment

Access this computer from the network <Not defined>

Act as part of the operating system <None>

Add workstations to domain <Not defined>

Adjust memory quotas for a process <Not defined>

Allow log on locally Administrators

Allow log on through terminal services Administrators, Remote Desktop Users

Back up files and directories Administrators

Bypass traverse checking Users

Change the system time Administrators

Create a pagefile <Not defined>

Create a token object <None>

Create a global object <Not defined>

Create permanent shared objects <None>

Debug programs <None>

Deny access to this computer from the network ANONYMOUS LOGON, Guests

Deny log on as a batch job Guests

Deny log on as a service <Not defined>

Deny log on locally <Not defined>

Deny log on through Terminal Service Guests

Enable computer and user accounts to be trusted for delegation

<None>

Force shutdown from a remote system <Not defined>

Generate security audits <Not defined>

Page 130: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

122 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Impersonate a client after authentication SERVICE

Increase scheduling priority <Not defined>

Load and unload device drivers Administrators

Lock pages in memory <Not defined>

Log on as batch job <None>

Log on as a service <Not defined>

Manage auditing and security log <Not defined>

Modify firmware environment values <Not defined>

Perform volume maintenance tasks <Not defined>

Profile single process <Not defined>

Profile system performance <Not defined>

Remove computer from docking station <Not defined>

Replace a process level token LOCAL SERVICE, NETWORK SERVICE

Restore files and directories <Not defined>

Shutdown the system Administrators

Synchronize directory service data <None>

Take ownership of file or other objects Administrators

Security Options

Accounts: Administrator account status <Not defined>

Accounts: Guest account status Disabled

Accounts: Limit local account use of blank passwords to console logon only

Enabled

Accounts: Rename administrator account <Not defined>

(recommend to change it to a non-standard name)

Accounts: Rename guest account <Not defined>

(recommend to change it to a non-standard name)

Audit: Audit the access of global system objects <Not defined>

Page 131: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 123

Audit: Audit the use of backup and restore privilege <Not defined>

Audit: Shut down system immediately if unable to log security alerts

<Not defined>

DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax

<Not defined>

Devices: Allow undock without having to log on <Not defined>

Devices: Allowed to format and eject removal media Administrators

Devices: Prevent users from installing printer drivers Enabled

Devices: Restrict CD-ROM access to locally logged-on user only

<Not defined>

Devices: Restrict floppy access to locally logged-on user only

<Not defined>

Devices: Unsigned driver installation behavior Warn but allow installation

Domain Controller: Allow server operators to schedule tasks

<Not defined>

(Not applicable)

Domain Controller: LDAP server signing requirements <Not defined>

(Not applicable)

Domain Controller: Refuse machine account password changes

<Not defined>

(Not applicable)

Domain member: Digitally encrypt or sign secure channel data (always)

<Not defined>

Domain member: Digitally encrypt secure channel data (when possible)

Enabled

Domain member: Digitally sign secure channel data (when possible)

Enabled

Domain member: Disable machine account password changes

Disabled

Domain member: Maximum machine password age 30 days

Domain member: Require strong (Windows 2000 or later) session key

Enabled

Interactive logon: Display user information when the session is locked

<Not defined>

Page 132: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

124 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Interactive logon: Do not display last user name Enabled

Interactive logon: Do not required CTRL+ALT+DEL Disabled

Interactive logon: Message text for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message text)

Interactive logon: Message title for users attempting to log on

<Not defined>

(Recommend to define a custom, or DOJ approved message title)

Interactive logon: Number of previous logons to cache (in case domain controller is not available)

<Not defined>

Interactive logon: Prompt user to change password before expiration

14 days

Interactive logon: Require domain controller authentication to unlock workstation

<Not defined>

Interactive logon: Require smart card <Not defined>

Interactive logon: Smart card removal behavior Lock Workstation

Microsoft network client: Digitally sign communications (always)

Enabled

Microsoft network client: Digitally sign communications (if server agrees)

Enabled

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

Disabled

Microsoft network server: Amount of idle time required before suspending session

15 minutes

Microsoft network server: Digitally sign communications (always)

<Not defined>

Microsoft network server: Digitally sign communications (if client agrees)

Enabled

Microsoft network server: Disconnect clients when logon hours expire

Enabled

MSS: (AFD DynamicBacklogGrowthDelta) Number of connections to create when additional connections are necessary for Winsock applications (10 recommended)

10

MSS: (AFD EnableDynamicBacklog) Enable dynamic backlog for Winsock applications (recommended)

Enabled

MSS: (AFD MaximumDynamicBacklog) Maximum number of ‘quasi-free’ connections for Winsock

20000 (recommended)

Page 133: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 125

applications

MSS: (AFD MinimumDynamicBacklog) Minimum number of free connections for Winsock applications (20 recommended for system under attack, 10 otherwise)

20

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Highest protection, source routing is completely disabled

MSS: (EnableDealGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)

Disabled

MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes

Disabled

MSS: (EnablePMTUDiscovery) Allow automatic detection of MTU size (possible DoS by an attacker using a small MTU)

<Not defined>

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers

Enabled

MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure DefaultGateway addresses (could lead to DoS)

Disabled

MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)

Connections time out sooner of a SYN attach is detected

MSS: (TCPMaxConnectREsponseRetransmission) SYN-ACK retransmissions when a connection request is not acknowledged

3 & 6 secopnds, half-open connections dropped after 21 seconds

MSS: (TCPMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)

3

MSS: (TCPMazPortalExhausted) How many dropped connect requests to initiate SYN attack protection (5 is recommended)

5

MSS: Disable Autorun for all drives 255, disable Autorun for all drives

MSS: Enable Safe DLL search mode Enabled

MSS: Enable the computer to stop generating 8.3 style filenames

<Not defined>

MSS: How often keep-alive packets are sent in milliseconds

300000 or 5 minutes (recommended)

MSS Percentage threshold for the security event log at which the system will generate a warning

<Not defined>

MSS: The time in seconds before the screen saver grace period expires

0

Page 134: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

126 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Network access: Allow anonymous SID//Name translation Disabled

Network access: Do not allow anonymous enumeration of SAM accounts

Enabled

Network access: Do not allow anonymous enumeration of SAM accounts and shares

Enabled

Network access: Do not allow storage of credentials or .NET passports for network authentication

Enabled

Network access: Let Everyone permissions apply to anonymous users

Disabled

Network access: Named pipes that can be accessed anonymously

<None>

Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions

System\CurrentControlSet\Control\Server Applications

Software\Microsoft\WindowsNT\CurrentVersion

Network access: Remotely accessible registry paths and sub-paths

Software\Microsoft\WindowsNT\CurrentVersion\Print

Software\Microsoft\WindowsNT\CurrentVesion\Windows

System\CurrentControlSet\Control\Print\Printers

System\CurrentControlSet\Services\Eventlog

Software\Microsoft\OLAP Server

System\CurrentControlSet\Control\ContentIndex

System\CurrentControlSet\Control\Terminal Server\UserConfig

System\CurrentControlSet\Control\Terminal Server\Default\UserConfiguration

Software\Micrsoft\WIndowsNT\CurrentVersion\Perflib

System\CurrentControlSet\Services\SysmonLog

Network access: Restrict anonymous access to Named Pipes and Shares

Enabled

Page 135: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 127

Network access: Shares that can be accessed anonymously <None>

Network access: Sharing and security model for local accounts

Classic – local users authenticate as themselves

Network security: Do not store LAN Manager password hash value on next password change

Enabled

Network security: Force logoff when logon hours expire <Not defined>

Network security: LAN Manager authentication level Send NTLMv2 response only\refuse LM

Network security: LDAP client signing requirements Negotiate signing

Network security: Minimum session security for NTLM SSP based (including secure RPC) clients

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Network security: Minimum session security for NTLM SSP based (including secure RPC) servers

Require message integrity

Require message confidentiality

Require NTLMv2 Session Security

Require 128-bit Encryption

Recovery console: Allow automatic administrative logon Disabled

Recovery console: Allow floppy copy and access to all drives and all folders

<Not defined>

Shutdown: Allow system to be shut down without having to log on

Disable

Shutdown: Clear virtual memory pagefile <Not defined>

System cryptography: Force strong key protection for user keys stored on computer

User must enter a password each time they use a key

System cryptography: User FIPS compliant algorithms for encryption, hashing, and signing

<Not defined>

System objects: Default owner for objects created by members of the Administrations group

<Not defined>

System objects: Require case insensitive for non-Windows subsystems

<Not defined>

System objects: Strengthen default permission of internal system objects

Enabled

System settings: Option subsystems <None>

Page 136: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

128 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

System settings: User Certificate Rules on Windows Executables for Software Restriction Policies

<Not defined>

Event Logs

Maximum application log size 16384 kilobytes

Maximum security log size 81920 kilobytes

Maximum system log size 16384 kilobytes

Prevent local guests group from accessing application log Enabled

Prevent local guests group from accessing security log Enabled

Prevent local guests group from accessing system log Enabled

Retain application log <Not defined>

Retain security log <Not defined>

Retain system log <Not defined>

Retention method for application log <Not defined>

Retention method for security log <Not defined>

Retention method for system log <Not defined>

Restricted Groups

<Not defined>

System Services

Alerter

(Alerter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Application Experience Lookup Service

(AeLookupSvc)

(applicable to Windows Server 2003 SP1)

<Not defined>

Application Layer Gateway Service

(ALG)

<Not defined>

Application Management

(AppMgmt)

<Not defined>

Client Service for Netware Disabled

Page 137: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 129

(NWCWorkstation) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

ASP.NET State Service

(aspnet_state)

<Not defined>

Automatic Updates

(Wuauserv)

<Not defined>

Background Intelligent Transfer Service

(BITS)

<Not defined>

CC License Manager

(CC_LM)

(Built-in CC 6.0 service)

<Not defined>

CC Replication Service

(REP_Service)

(Built-in CCMS service

<Not defined>

CCMS ASM_Service

(ASM_Service)

(Built-in CCMS Service)

<Not defined>

CCMS Audit_Service

(AUDIT_Service)

(Built-in CCMS service)

<Not defined>

CCMS Control Service

(CCMS_MasterService)

(Built-in CCMS service)

<Not defined>

CCMS DBNotifier_Service

(DBNotifier_Service)

(Built-in CCMS service)

<Not defined>

CCMS EB_Service

(EB_Service)

(Built-in CCMS service)

<Not defined>

Page 138: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

130 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

CCMS ES_Service

(ES_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDC_Service

(HDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS HDM_Service

(HDM_Service)

(Built-in CCMS service)

<Not defined>

CCMS Host Application Integration

(Host Application Integration)

(Built-in CCMS service)

<Not defined>

CCMS IS_Service

(IS_Service)

(Built-in CCMS service)

<Not defined>

CCMS MAS Backup/Restore

(nbbkp)

(Built-in CCMS service)

<Not defined>

CCMS MAS Configuration Manager

(nbcfg)

(Built-in CCMS service)

<Not defined>

CCMS MAS Event Scheduler

(nbsch)

(Built-in CCMS service)

<Not defined>

CCMS MAS Fault Manager

(nbflt)

(Built-in CCMS service)

<Not defined>

CCMS MAS LinkHandler Port #2 <Not defined>

Page 139: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 131

(nbalh)

(Built-in CCMS service)

CCMS MAS OM Server

(nboms)

(Built-in CCMS service)

<Not defined>

CCMS MAS Security

(nbss)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Daemon

(nbsm_dae)

(Built-in CCMS service)

<Not defined>

CCMS MAS Service Manager

(nbsm)

(Built-in CCMS service)

<Not defined>

CCMS MAS Time Service

(nbts)

(Built-in CCMS service)

<Not defined>

CCMS MLSM_Service

(MLSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBMSM_Service

(CCMS_NBMSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBNM_Service

(NBNM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NBTSM_Service

(NBTSM_Service)

<Not defined>

Page 140: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

132 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Built-in CCMS service)

CCMS NCCOAM_Service

(NCCOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NDLOAM_Service

(NDLOAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NIMSM_Service

(CCMS_NIMSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS NINCCAudit_Service

(NINCCAudit_Service)

(Built-in CCMS service)

<Not defined>

CCMS NITSM_Service

(NITSM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAM_Service

(OAM_Service)

(Built-in CCMS service)

<Not defined>

CCMS OAMCMF_Service

(CCMS_OAM_CMF_Service)

(Built-in CCMS service)

<Not defined>

CCMS RDC_Service

(RDC_Service)

(Built-in CCMS service)

<Not defined>

CCMS RSM_Service

(RSM_Service)

(Built-in CCMS service)

<Not defined>

Page 141: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 133

CCMS SDMCA_Service

(SDMCA_Service)

(Built-in CCMS service)

<Not defined>

CCMS SDP_Service

(SDP_Service)

(Built-in CCMS Service)

<Not defined>

CCMS SIP_Service

(CCMS_SIP_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFA_Service

(TFA_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFABRIDGE_Service

(TFABRIDGE_Service)

(Built-in CCMS service)

<Not defined>

CCMS TFE Bridge Connector

(TfeBridgeConnector)

(Built-in CCMS service)

<Not defined>

CCMS TFE_Service

(TFE_Service)

(Built-in CCMS service)

<Not defined>

CCMS UNE_Service

(CCMS_UNE_Service)

(Built-in CCMS service)

<Not defined>

CCMS VSM_Service

(VSM_Service)

(Built-in CCMS service)

<Not defined>

ClipBook Disabled

Page 142: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

134 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(ClipSrv) (Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

COM+ Event System

(EventSystem)

<Not defined>

COM+ System Application

(COMSysApp)

<Not defined>

Computer Browser

(Browser)

<Not defined>

Cryptographic Services

(CryptSvc)

<Not defined>

DCOM Server Process Launcher

(DcomLaunch)

(applicable to Windows Server 2003 SP1)

<Not defined>

DHCP Client

(Dhcp)

<Not defined>

Distributed File System

(Dfs)

<Not defined>

Distributing Link Tracking Client

(TrkWks)

<Not defined>

Distributing Link Tracking Server

(TrkSvr)

<Not defined>

Distributed Transaction Coordinator

(MSDTC)

<Not defined>

DNS Client

(Dnscache)

<Not defined>

Error Reporting Services

(ERSvc)

<Not defined>

Event Log

(Eventlog)

<Not defined>

Page 143: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 135

Fax

(Fax)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Replication

(NtFrs)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

File Server for Macintosh

(MacFile)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

FTP Publishing Service

(MSFtpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Help & Support

(Helpsvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

HTTP SSL

(HTTPFilter)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Human Interface Device Access

(HidServ)

<Not defined>

IIS Admin Service

(IISADMIN)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

IMAP CD-Burning COM Service

(ImapiService)

<Not defined>

Indexing Service

(Cisvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

InstallDriver Table Manager

(Built-in InstallShield service for CC installation)

<Not defined>

Intersite Messaging

(IsmServ)

<Not defined>

Page 144: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

136 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

IPSEC Service

(PolicyAgent)

<Not defined>

Kerberos Key Distribution Center

(Kdc)

<Not defined>

License Logging Service

(LicenseService)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Logical Disk Manager

(Dmserver)

<Not defined>

Logical Disk Manager Administrative Service

(Dmadmin)

<Not defined>

Messenger

(Messenger)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft POP3 Service

(POP3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Microsoft Software Shadow Copy Provider

(SwPrv)

<Not defined>

Net Logon

(Netlogon)

<Not defined>

NetMeeting Remote Desktop Sharing

(mnmsrvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network Connections

(Netman)

Manual

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Network DDE

(NetDDE)

<Not defined>

Network DDE DSDM

(NetDDEdsdm)

<Not defined>

Page 145: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 137

Network Location Awareness

(NLA)

<Not defined>

Network Provisioning Service

(xmlprov)

(applicable to Windows Server 2003 SP1)

<Not defined>

Network News Transport Protocol (NNTP)

(NntpSvc)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

NT LM Security Support Provider

(NtLmSsp)

<Not defined>

pcAnywhere Host Service

(Built-in pcAnywhere service for CC if it is installed)

<Not defined>

Performance Logs and Alerts

(SysmonLog)

<Not defined>

Plug and Play

(PlugPlay)

<Not defined>

Portable Media Serial Number Service

(WmdmPmSN)

<Not defined>

Print Server for Macintosh

(MacPrint)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Print Spooler

(Spooler)

<Not defined>

Protect Storage

(ProtectedStorage)

<Not defined>

Remote Access Auto Connection Manager

(RasAuto)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Access Connection Manager

(RasMan)

<Not defined>

Page 146: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

138 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Remote Administration Service

(SrvcSurg)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Desktop Help Session Manager

(RDSessMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Installation

(BINLSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Procedure Call (RPC)

(RpcSs)

<Not defined>

Remote Procedure Call (RPC) Locator

(RpcLocator)

<Not defined>

Remote Registry

(RemoteRegistry)

<Not defined>

Remote Server Manager

(AppMgr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Server Monitor

(Appmon)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Notification

(Remote_Storage_User_Link)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Remote Storage Server

(Remote_Storage_Server)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Removal Storage

(NtmsSvc)

<Not defined>

Resultant Set of Policy Provider

(RSoPProv)

<Not defined>

Routing and Remote Access <Not defined>

Page 147: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 139

(RemoteAccess)

Secondary Logon

(seclogon)

<Not defined>

Security Accounts Manager

(SamSs)

<Not defined>

Server

(lanmanserver)

<Not defined>

Shell Hardware Detection

(ShellHWDetection)

<Not defined>

Simple Mail Transfer Protocol (SMTP)

(SMTPSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Smart Card

(SCardSvr)

<Not defined>

SNMP Service

(SNMP)

<Not defined>

SNMP Trap Service

(SNMPTRAP)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Special Administration Console Helper

(Sacsvr)

<Not defined>

Sybase BCKServer_<server name>_BS

(SYBBCK_<server name>_BS)

(Built-in CCMS Sybase service)

<Not defined>

Sybase MONServer_<server name>_MS

(SYBMON_<server name>_MS)

(Built-in CCMS Sybase service)

<Not defined>

Sybase SQLServer_<server name>

(SYBSQL_<server name>)

<Not defined>

Page 148: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

140 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(Built-in CCMS Sybase service)

Sybase XPServer_<server name>_XP

(SYBXPS_<server name>_XP)

(Built-in CCMS Sybase service)

<Not defined>

Sybase ASE Protect Service

(SybProtect)

(Built-in CCMS Sybase service)

<Not defined>

System Event Notification

(SENS)

<Not defined>

TAO NT Naming Service

(TAO_NT_Naming_Service)

(Built-in CCMS TAO service)

<Not defined>

Task Scheduler

(Schedule)

<Not defined>

TCP/IP NetBIOS Helper Service

(LMHosts)

<Not defined>

Telephony

(TapiSrv)

<Not defined>

Telnet

(TlntSvr)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Terminal Services

(TermService)

<Not defined>

Terminal Service Session Directory

(Tssdis)

<Not defined>

Trivial FTP Daemon

(tftpd)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Themes <Not defined>

Page 149: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 141

(Themes)

Uninterruptible Power Supply

(UPS)

<Not defined>

Upload Manager

(Uploadmgr)

<Not defined>

Virtual Disk Service

(VDS)

<Not defined>

Volume Shadow Copy

(VSS)

<Not defined>

Web Element Manager

(elementmgr)

<Not defined>

WebClient

(WebClient)

<Not defined>

Windows Audio

(AudioSrv)

<Not defined>

Windows Firewall/Internet Connection Sharing (ICS)

(SharedAccess)

<Not defined>

Windows Image Acquisition (WIA)

(StiSvc)

<Not defined>

Windows Installer

(MSIServer)

<Not defined>

Windows Management Instrumentation

(winmgmt)

<Not defined>

Windows Management Instrumentation Driver Extensions

(Wmi)

<Not defined>

Windows Time

(W32Time)

<Not defined>

Windows User Mode Driver Framework <Not defined>

Page 150: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

142 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

(UMWdf)

(applicable to Windows Server 2003 SP1)

WinHTTP Web Proxy Auto-Discovery Service

(WinHttpAutoProxySvc)

<Not defined>

Wireless Configuration

(WZCSVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

WMI Performance Adapter

(WmiApSrv)

<Not defined>

Workstation

(lanmanworkstation)

<Not defined>

World Wide Web Publishing Service

(W3SVC)

Disabled

(Permissions: Administrators=Full Control, System=Full Control, Interactive=Read)

Registry

MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer

Administrators=Full Control, SYSTME=Full Control, Users=Read

MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies

Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Enum Administrators=Full Control, Authenticate Users=Read, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentConrtrolSet\Services\SNMP\Parameters\PermittedManagers

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters\ValidCommunities

Administrators=Full Control, CREATOR OWNER=Full Control, SYSTEM=Full Control

USERS\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Administrators=Full Control, SYSTME=Full Control, Users=Read

File System

%SystemRoot%\regedit.exe Administrators=Full Control, SYSTEM=Full Control

Page 151: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 143

%SystemRoot%\system32\at.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\attrib.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\cacls.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\debug.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwatson.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\drwtsn32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\edlin.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventcreate.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\eventtriggers.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\ftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\net1.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\netsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rcp.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\reg.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regedt32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\regsvr32.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\rexec.exe Administrators=Full Control, SYSTEM=Full

Page 152: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

144 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

Control

%SystemRoot%\system32\rsh.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\runas.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\sc.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\subst.exe Administrators=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\telnet.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tftp.exe Administrators=Full Control, INTERACTIVE=Full Control, SYSTEM=Full Control

%SystemRoot%\system32\tlntsvr.exe Administrators=Full Control, SYSTEM=Full Control

Page 153: CCMS 6.0 Security Templates

Contact Center 6.0 Security Template Files Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 145

[ This page is left intentionally blank ]

Page 154: CCMS 6.0 Security Templates

Glossary Nortel Proprietary

146 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

4 Glossary

The glossary provided relates solely to this document.

CLAN Customer Local Area Network

DHCP Dynamic Host Connection Protocol

DNS Domain Name Service

ELAN Embedded Local Area Network

IT Information Technology

LAN Local Area Network

MAS Meridian Application Server

NCC Network Control Center

Nortel Servers Subnet Previously known as CLAN

PC Personal Computer

PEP Performance Enhancement Package

PRD Platform Recovery Disk

RAS Remote Access Service

SCCS Symposium Call Center Server

SMTP Simple Mail Transfer Protocol

SU Service Update

SWC Symposium Call Center Web Client

TAPI SP Symposium TAPI Service Provider

WAN Wide Area Network

Page 155: CCMS 6.0 Security Templates

Glossary Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide 147

[ This page is left intentionally blank ]

Page 156: CCMS 6.0 Security Templates

References Nortel Proprietary

148 Nortel Contact Center 6.0 Security Templates User Guide Issue 1.02

5 References [1] Windows Server 2003 Operating System Legacy, Enterprise, and Specialized Security

Benchmark Consensus Security Settings for Domain Member Servers, Version 1.2, October 17, 2005, The Center for Internet Security

[2] Contact Center 6.0 Security Guide, issue 1.01, July 18 2006

Page 157: CCMS 6.0 Security Templates

Nortel Proprietary

Issue 1.02 Nortel Contact Center 6.0 Security Templates User Guide

[ Last Page ]