pkobres
Posts: 8
Score: 0 Joined: 6/5/2007 Status: offline
|
I'm hoping someone on the forums might be able to help us understand the mechanism by which we DOSed our SMS advanced clients on a local subnet over the weekend. (besides the obvious....) Senerio: Advanced clients are deployed in a production environment w/ SMS2003 using advanced security (but no schema extensions).... The client's managment point is hard coded into the client installation command line. Clients are discovered by our production SMS server using AD methods only. Our site boundary is our AD (no networks). Our SMS Test server, which is on a different AD, and uses different credentials, but happens to share the same site code, was unknowingly plugged into our production network for a short period of time. (Ding! Yes... fist problem right there...) The test server, was only partially configured, having no site boundaries defined, and all AD discovery methods were limited to a non-existant container in a different AD. Heartbeat discovery, however, was turned on , as was network discovery. Though "local subnets" were not defined, "search local subnet" was enabled. The result was that a number of advanced clients on the same local subnet as the test server, changed their managment points to point to the IP address of the test box. The clients show up as assigned on the test box, even though they're in a different AD, and heart-beat discovery is the only method listed when looking at the discovery data for each client. I'm trying to figure out under what security authority this happened. There was no WINS server setup. The SMS test box should have had no authority over machines in the production environment or within the production domain. Why would the previously installed production advanced clients just decide to trust an unknown managment point that happened to have the same site code? I'd love to extend the schema, but we as of yet have no enterprise PKI (making certificates authentication of the managment point useless) and our environment has several independently run SMS or SCCM servers, which need different extensions as I understand. Any thoughts would be appreciated! Thanks!
|