/build/static/layout/Breadcrumb_cap_w.png

Security policies that give you grief.

The reason I make a gripe list is because I believe there is a balance between necessary security and functionality. We all know vendors make bad architectural decisions with their applications and sometimes utopian security concepts cause more grief than reduction of support costs and real world security. I have been scripting in some secure environments and I'd like to see what policies have caused you grief. Here is my list of top security configurations that have caused me fun.


Windows Installer's DisableBrowse has caused upgrades using different source paths and REINSTALL=ALL to fail.

Restriciting access to the security eventlog will prevent Windows Installer 3.1 from installing.

Locking down access to HKCR for end users causes huge ammounts of scripting overhead finding all the registry keys that need to be opened up so the app will work. Maybe it is the apps I work with but you'd be suprised how many apps need to manipulate this hive.

Enabling cab signing is more of a pain in the ______. Apps that do not allow you to make an administrative installation but use many cab files require some jumping through hoops to sign all the cabs.

0 Comments   [ + ] Show comments

Answers (2)

Posted by: kkaminsk 17 years ago
9th Degree Black Belt
0
Found a new one. Not allowing users to have the right to create global objects will break a few applications. Most notibly Oracle 10 and Exceed 11.
Posted by: revizor 17 years ago
Third Degree Blue Belt
0
ORIGINAL: kkaminsk

Found a new one. Not allowing users to have the right to create global objects will break a few applications. Most notibly Oracle 10 and Exceed 11.


Add CICS to that list...
Rating comments in this legacy AppDeploy message board thread won't reorder them,
so that the conversation will remain readable.

Don't be a Stranger!

Sign up today to participate, stay informed, earn points and establish a reputation for yourself!

Sign up! or login

View more:

Share

 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ