You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
401 lines
27 KiB
401 lines
27 KiB
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
|
|
|
|
<HTML DIR="LTR">
|
|
<HEAD>
|
|
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
|
|
|
|
<META HTTP-EQUIV="MSThemeCompatible" CONTENT="Yes">
|
|
|
|
<META NAME="MS.LOCALE" CONTENT="EN-US">
|
|
|
|
<META NAME="DESCRIPTION" LOCCONTENT="Release Notes for the Windows Server 2003 Family">
|
|
|
|
<TITLE>Release Notes for the Windows Server 2003 Family</TITLE>
|
|
<STYLE type="text/css">
|
|
<!--
|
|
H1 {CLEAR: both; FONT-SIZE: 140%; MARGIN-BOTTOM: 0.5em}
|
|
H2 {CLEAR: both; MARGIN-TOP: 1.5em; FONT-SIZE: 130%; MARGIN-BOTTOM: 0.5em}
|
|
H4 {CLEAR: both; MARGIN-TOP: 1.2em; FONT-SIZE: 110%; MARGIN-BOTTOM: 0.5em; MARGIN-LEFT: 1em}
|
|
|
|
P {MARGIN-TOP: 1.5em; MARGIN-BOTTOM: 0.6em}
|
|
P.indent {MARGIN-TOP: .5em; MARGIN-LEFT: 2.1em }
|
|
P.note {CLEAR: both; MARGIN-TOP: 1em; FONT-WEIGHT: bold; MARGIN-BOTTOM: -0.25em}
|
|
|
|
|
|
OL {MARGIN-TOP: 0.5em; PADDING-LEFT: 0em; MARGIN-BOTTOM: 0px; MARGIN-LEFT: 2.1em}
|
|
|
|
UL {MARGIN-TOP: 0.6em; PADDING-LEFT: 0em; MARGIN-BOTTOM: 0px; MARGIN-LEFT: 1.5em; LIST-STYLE-TYPE: disc}
|
|
|
|
LI {CLEAR: both; MARGIN-BOTTOM: 0.7em}
|
|
|
|
BODY {FONT-SIZE: 80%; BACKGROUND: #ffffff; COLOR: #000000; FONT-FAMILY: Verdana, Arial, Helvetica, Sans Serif}
|
|
|
|
TABLE {FONT-SIZE: 100%; BACKGROUND: #ffffff; COLOR: #000000; FONT-FAMILY: Verdana, Arial, Helvetica, Sans Serif}
|
|
|
|
A:link {COLOR: #0066cc; TEXT-DECORATION: none}
|
|
A:visited {COLOR: #0066cc; TEXT-DECORATION: none}
|
|
A:hover {COLOR: #ff0000; TEXT-DECORATION: underline}
|
|
A:active {COLOR: #ff0000; TEXT-DECORATION: underline}
|
|
HR {HEIGHT: 1px}
|
|
|
|
A.finePrint {font-size: 85%;}
|
|
-->
|
|
</STYLE>
|
|
</HEAD>
|
|
<BODY>
|
|
<img src="Wnet_h_s_rgb_ai.gif" width="578" height="104" border="0" alt="Microsoft Windows Server 2003">
|
|
<BR><BR>
|
|
|
|
<H1><A NAME="microsoft_windows_net_serverbeta_3_release_notes_hqqu"></A> Release Notes</H1>
|
|
|
|
<HR>
|
|
|
|
<H4><A HREF="#how_to_use_these_notes_opsd">How to Use These Notes</A></H4>
|
|
|
|
<H4><A HREF="#applications_eyhz">Applications</A></H4>
|
|
|
|
<H4><A HREF="#change_and_configuration_bhbt">Change and Configuration</A></H4>
|
|
|
|
<H4><A HREF="#clustering_rsrd">Clustering</A></H4>
|
|
|
|
<H4><A HREF="#directory_services_gxoh">Directory Services</A></H4>
|
|
|
|
<H4><A HREF="#internet_services_cgyp">Internet Services</A></H4>
|
|
|
|
<H4><A HREF="#network_and_communications_nyrx">Network and Communications</A></H4>
|
|
|
|
<H4><A HREF="#security_whcv">Security</A></H4>
|
|
|
|
<H4><A HREF="#additional_resources_uwuy">Additional Resources</A></H4>
|
|
|
|
<P><A HREF="#copyright_gwtm">© 2003 Microsoft Corporation. All rights reserved</A>.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="how_to_use_these_notes_opsd"></A> How to Use These Notes</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<P>Welcome to the release notes for the Windows Server 2003 family. These release notes contain important information that was not available when the documentation for the Windows Server 2003 family was written. The Windows Server 2003 family includes the following products:</P>
|
|
|
|
<UL>
|
|
<LI>Windows Server 2003, Standard Edition </li>
|
|
<LI>Windows Server 2003, Enterprise Edition </li>
|
|
<LI>Windows Server 2003, Datacenter Edition </li>
|
|
<LI>Windows Server 2003, Web Edition </li>
|
|
</UL>
|
|
|
|
<P>Release notes that start with a list of products apply only to the products that are listed with the note. All other notes apply to all products in the Windows Server 2003 family.</P>
|
|
|
|
<P>In addition to this file, you should read several other files in the \Docs folder on your operating system disc:</P>
|
|
|
|
<UL>
|
|
<LI>Read1st.txt contains release notes that you should read before you install a product in the Windows Server 2003 family.</li>
|
|
<LI>Setup text files contain important information about the installation process.</li>
|
|
</UL>
|
|
|
|
<P>You can find additional information at the Web sites that are listed at the end of this document.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="applications_eyhz"></A> Applications</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="16_bit_applications__udms"></A> 16-bit applications </H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition (64-bit version only); Windows Server 2003, Datacenter Edition (64-bit version only)</P>
|
|
|
|
<P>These products do not support most 16-bit applications. </P>
|
|
|
|
<P>Most 32-bit applications that use 16-bit Microsoft ACME Setup versions 2.6, 3.0, 3.01, and 3.1 and InstallShield versions 5.x install correctly.</P>
|
|
|
|
<P>No 32-bit applications that are installed by other 16-bit setup programs are supported. If you try to install one of these applications, the message "\Setup.exe is not a valid Win32 application" appears, and the setup program closes without installing or starting the application.</P>
|
|
|
|
<H2><A NAME="32_bit_device_drivers__vyni"></A> 32-bit device drivers</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition (64-bit version only); Windows Server 2003, Datacenter Edition (64-bit version only)</P>
|
|
|
|
<P>These products do not support 32-bit device drivers. Applications that depend on 32-bit device drivers will not function correctly and might cause an error during installation or operation. Most 32-bit antivirus programs are affected and should not be installed on computers that are running these products.</P>
|
|
|
|
<P>If Windows does not start after you attempt to install a 32-bit driver, start the computer using the last known good configuration as follows:</P>
|
|
|
|
<OL>
|
|
<LI>Restart the computer.</li>
|
|
<LI>When the message "<B>Please select the operating system to start</B>" appears, press F8.</li>
|
|
<LI>Press an arrow key to highlight <B>Last Known Good Configuration</B>, and then press ENTER. </li>
|
|
<LI>Press an arrow key to highlight an operating system, press ENTER, and follow the instructions.</li>
|
|
</OL>
|
|
<P class="note">Note</P>
|
|
<P class="indent">Completing this procedure provides a way to recover from problems such as a newly added driver that is incorrect for your hardware. It does not solve problems caused by drivers or files that are corrupted or missing. When you start the computer using the last known good configuration, only the information in the registry key HKLM\System\CurrentControlSet is restored. Any changes that you have made in other registry keys remain.</P>
|
|
|
|
<H2><A NAME="internet explorer__and_32_bit_web_components_wkog"></A> Internet Explorer and 32-bit Web components</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition (64-bit version only); Windows Server 2003, Datacenter Edition (64-bit version only)</P>
|
|
|
|
<P>The 64-bit version of Internet Explorer will not load 32-bit Web components from Microsoft, such as the MSN® Money Ticker, or 32-bit Web components from companies other than Microsoft. To load these components, use the 32-bit version of Internet Explorer. </P>
|
|
|
|
<P>To open the 32-bit version of Internet Explorer, click <B>Start</B>, click <B>All Programs</B>, and then click <B>Internet Explorer (32-bit)</B>.</P>
|
|
|
|
<H2><A NAME="microsoft_agent_hsav"></A> Microsoft Agent</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition (32-bit version only)</P>
|
|
|
|
<P>These products provide inbox support for Speech Application Programming Interface (SAPI) version 5.0 engines and programs. To avoid loss of functionality in Microsoft Agent applications that use SAPI version 4.0 speech input and/or output engines, you must install SAPI version 4.0a run-time support and then reinstall the SAPI version 4.0 speech engines, even if they were working with Microsoft Agent before you upgraded. To install SAPI version 4.0a run-time support, click <A HREF="http://go.microsoft.com/fwlink/?LinkId=3354" TARGET="_blank"><U>here</U></A>. </P>
|
|
|
|
<H2><A NAME="microsoft_exchange_server_kfal"></A> Microsoft Exchange Server</H2>
|
|
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition (32-bit version only); Windows Server 2003, Datacenter Edition (32-bit version only)</P>
|
|
|
|
<P>You cannot install Exchange Server 2000 on a server that is running any product in the Windows Server 2003 family. </P>
|
|
|
|
<P>Installing a beta release of Exchange Server 2003 on a server that is running one of these products is supported in test labs but not in production environments. You can use a beta release of Exchange Server 2003 in Active Directory® forest environments in which all domain controllers are running products in the Microsoft Windows 2000 Server family. However, you must have at least one domain controller that is running one of the products listed for this note to access all of the new features of that beta release. For information about which features have this requirement, see the online Help for the beta release that you want to use and the document, <I>Microsoft Exchange Server 2003 Getting Started Guide</I>, which ships with beta releases of Exchange Server 2003. Beta releases of Exchange Server 2003 are available from the <A HREF="http://go.microsoft.com/fwlink/?LinkId=309" TARGET="_blank"><U>Microsoft Exchange Server Web site</U></A>.</P>
|
|
|
|
<P>If you upgrade a domain controller or a global catalog server to one of the products listed for this note, any Exchange servers in that domain must be running Exchange Server 2000 with Service Pack 2 or Service Pack 3.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="change_and_configuration_bhbt"></A> Change and Configuration</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="redirection_of_new_users_and_computers_to_ou_s_prnh"></A> Redirection of new account locations to organizational units</H2>
|
|
|
|
<P>To simplify domain management, you should redirect the default locations for newly created user and computer accounts from the common name to organizational units within the domain. You must redirect these locations if you want to apply Group Policy settings. For details about how to redirect these locations, see article 324949, "Redirecting the Users and Computers Containers in Windows Server 2003 Domains" in the <A HREF="http://go.microsoft.com/fwlink/?LinkId=4441" TARGET="_blank"><U>Microsoft Knowledge Base</U></A>.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="clustering_rsrd"></A>Clustering</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="server_clusters_3__uavg"></A>Modifying a cluster security descriptor</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition; Windows Server 2003, Datacenter Edition</P>
|
|
|
|
<P>To modify the cluster security descriptor on a cluster that is running either of these products, you must use <B>Cluster Administrator</B> on a server that is running one of these products or that is running a product in the Windows 2000 Server family with Service Pack 2 or Service Pack 3. If you try to use a server that is running a product in the Windows 2000 Server family or a product in the Windows 2000 Server family with Service Pack 1, the following message appears when you try to save changes:</P>
|
|
|
|
<BLOCKQUOTE>"Access to the cluster can be granted/denied only
|
|
to domain users and groups. Please use the Security
|
|
tab to remove the local users or groups."</BLOCKQUOTE>
|
|
|
|
<P>For more information, see article 812875, "A Computer running Windows 2000 Cannot Administer the CSD Using the Cluster Administration Utility" in the <A HREF="http://go.microsoft.com/fwlink/?LinkId=4441" TARGET="_blank"><U>Microsoft Knowledge Base</U></A>.</P>
|
|
|
|
<H2><A NAME="server_clusters_wmsh"></A>Starting the Cluster service</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition; Windows Server 2003, Datacenter Edition</P>
|
|
|
|
<P>After you upgrade a cluster node from Windows 2000 to one of these products, you must log on with an account that is a member of both the Domain Admins group and the Administrators group on each cluster node before you can restart the Cluster service. This step is required even if the Domain Admins group is already a member of the Administrators group on each cluster node.</P>
|
|
|
|
<P>If you log on with an account that does not meet these criteria and then try to start the Cluster service, the following message appears in the Event Log: <BLOCKQUOTE>"Volume Shadow Copy Service error: The process that hosts the writer with <name> and <ID> does not run under a user with sufficient access rights. Consider running this process under a local account which is either Local System, Administrator or Backup operator."</BLOCKQUOTE></P>
|
|
|
|
<H2><A NAME="server_clusters_2__kjtf"></A>Upgrading clusters from Windows NT Server 4.0</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Enterprise Edition; Windows Server 2003, Datacenter Edition</P>
|
|
|
|
<P>If you upgrade a cluster from Microsoft Windows NT Server 4.0 to one of the listed products, you cannot, by default, save changes to a cluster security descriptor.</P>
|
|
|
|
<P>If you are editing a descriptor using Cluster Administrator, the following error message appears when you try to save your changes: </P>
|
|
|
|
<BLOCKQUOTE>"The SYSTEM account must always have access to the cluster. Please use the Security tab to add the SYSTEM account."</BLOCKQUOTE>
|
|
|
|
<P>If you are editing a descriptor using the cluster.exe command-line utility, the following message appears when you try to save your changes:</P>
|
|
|
|
<BLOCKQUOTE>"The SYSTEM account must always have access to the cluster.
|
|
Please grant access to the SYSTEM account."</BLOCKQUOTE>
|
|
|
|
<P>To resolve this issue, see article 812876, "Clusters That Are Upgraded from Windows NT 4.0 Do Not Contain the System SID in the Security Descriptor" in the <A HREF="http://go.microsoft.com/fwlink/?LinkId=4441" TARGET="_blank"><U>Microsoft Knowledge Base</U></A>.</P>
|
|
<P class="note">Note</P>
|
|
<P class="indent">To upgrade from Windows NT Server 4.0 to a product in the Windows Server 2003 family, Service Pack 5 or Service Pack 6a must be installed first.</P>
|
|
|
|
<H2><A NAME="network_load_balancing_zwow"></A>Using Network Load Balancing Manager through a firewall</H2>
|
|
|
|
<P>To use Network Load Balancing Manager to manage servers through a firewall, you must set up your Distributed Component Object Model (DCOM) to use a specified range of ports and then configure the firewall to allow traffic through those ports as described in the white paper, <I>Using Distributed COM with Firewalls</I> on the <A HREF="http://go.microsoft.com/fwlink/?LinkId=14266" TARGET="_blank"><U>Microsoft Web site</U></A>. You must also either allow ICMP Echo Requests to pass through the firewall or start Network Load Balancing Manager with the /noping option. (At a command prompt, type <B>nlbmgr.exe /noping</B>.) For more information about using the /noping option, see the topic "Nlbmgr" in Help and Support Center.</P>
|
|
|
|
<P>If you do not follow these procedures, the error message "The RPC server is unavailable" or "Host unreachable" will appear. </P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="directory_services_gxoh"></A>Directory Services</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="administrative_tools_zrby"></A>Upgrade domain controllers running Windows 2000</H2>
|
|
|
|
<P>When using the Active Directory administration tools that are included with the Windows Server 2003 family to access domain controllers in a Windows 2000 domain, you must upgrade the domain controllers to Windows 2000 Service Pack 3 or you must revert to the default client policy for Lightweight Directory Access Protocol on the computer where the Active Directory administration tools are installed. </P>
|
|
|
|
<P>For more information, see article 325465, "Windows 2000 Domain Controllers Require SP3 or Later When Using Windows Server 2003 Administration Tools," in the <A HREF="http://go.microsoft.com/fwlink/?LinkId=4441" TARGET="_blank"><U>Microsoft Knowledge Base</U></A>. </P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="internet_services_cgyp"></A>Internet Services</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="internet_information_services_6_0_axig"></A>Internet Information Services (IIS) 6.0</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition; Windows Server 2003, Datacenter Edition </P>
|
|
|
|
<P>Because of increased security measures, the World Wide Web Publishing Service (WWW service) is not enabled by default in these products after you upgrade from the Windows 2000 Server family with IIS 5.0 unless you have completed one of these steps described for IIS 6.0 in read1st.txt (in the /Docs folder on the operating system disc) before upgrading. If you did not complete the steps described, you can enable and start the WWW service by using the Services snap-in:</P>
|
|
|
|
<OL>
|
|
<LI>Click <B>Start</B>, point to <B>Administrative Tools</B>, and then click <B>Services</B>. </li>
|
|
<LI>In the list of services, right-click <B>World Wide Web Publishing Service</B>, and then click <B>Properties</B>. </li>
|
|
<LI>On the <B>General</B> tab, in the <B>Startup type</B> list, click <B>Automatic</B>, and then click <B>OK</B>. </li>
|
|
<LI>In the list of services, right-click <B>World Wide Web Publishing Service</B>, and then click <B>Start</B>.</li>
|
|
</OL>
|
|
|
|
<P>Ensure that all unnecessary IIS features have been removed or disabled and that the enabled features are configured with the highest security settings that your organization can support. </P>
|
|
|
|
<P>For more information, see the topics "What’s Changed" and "Security Best Practices" in IIS 6.0 Help.</P>
|
|
|
|
<H2><A NAME="uddi_services__tlnh"></A> UDDI Services</H2>
|
|
|
|
<P><B>Products:</B> Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition (32-bit version only); Windows Server 2003, Datacenter Edition (32-bit version only)</P>
|
|
|
|
<P>You cannot run SQLXML (XML support for Microsoft SQL Server 2000 databases) and Universal Description, Discovery, and Integration (UDDI) Services on the same computer because SQLXML requires Internet Information Services (IIS) 5.0 isolation mode and UDDI Services requires IIS 6.0 worker process isolation mode.</P>
|
|
|
|
<P>Do not install SQLXML and UDDI Services on the same computer.</P>
|
|
|
|
<H2><A NAME="using_iis_with_active_server_pages_asp__ivky"></A> Using IIS with Active Server Pages</H2>
|
|
|
|
<P>The Windows Server 2003 family does not support Active Server Pages that use the mail object Collaboration Data Objects for Windows NT Server (CDONTS.dll) if you perform a new installation. The Windows Server 2003 family includes Collaborative Data Objects for Windows 2000 (CDOSYS.dll), which replaces CDONTS.dll.</P>
|
|
|
|
<UL>
|
|
<LI>If you upgrade to a product in the Windows Server 2003 family, Active Server Pages will use the existing CDONTS.dll file.</li>
|
|
<LI>If you perform a new installation of a product in the Windows Server 2003 family, you must copy CDONTS.dll from another computer to <NOBR>%windir%</NOBR>\system32 on the computer on which you performed the new installation. </li>
|
|
</UL>
|
|
|
|
<P>Microsoft recommends that you upgrade your Active Server Pages to use the new object.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="network_and_communications_nyrx"></A>Network and Communications</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="pop3_server_bdkh"></A>POP3 servers</H2>
|
|
|
|
<P>If you have configured a computer that is running a product in the Windows Server 2003 family as a mail server, you should not stop and restart the Simple Mail Transfer Protocol (SMTP) virtual server that is specific to the server that is running the POP3 service from IIS Manager in the Microsoft Management Console. Instead, you should stop and restart the SMTP service, either by using Services Manager or by using command-line tools.</P>
|
|
|
|
<P>If you stop and restart the SMTP virtual server rather than the SMTP service, all e-mail from the Internet will generate and send a Non-Delivery Report (NDR), and all internal e-mail will be sent to the SMTP Badmail folder. The SMTP and POP3 services will appear to run correctly, and no error message will appear. To restore functionality, you must stop and restart the Internet Information Services (IIS) service as described in the IIS 6.0 Help.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="security_whcv"></A>Security</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<H2><A NAME="ie_hardening_hadj"></A>Security restrictions on viewing Web pages and running executable files </H2>
|
|
|
|
<P>The default settings in Internet Explorer are more restrictive in the Windows Server 2003 family than in earlier versions of Windows. When you upgrade, any settings that do not match the new default settings will be overwritten. These changes decrease the exposure of your servers to attacks that are launched through Web content. However, users will not be able to view many Web pages correctly when using the default security settings. For users to see these Web pages correctly, you must explicitly grant access. In addition, users will not be able to run executable files from Universal Naming Convention (UNC) shared folders until you have added the shared computer to the Local intranet security zone in Internet Explorer. </P>
|
|
|
|
<P>For more information about security settings in Internet Explorer, see the online Help for Internet Explorer Enhanced Security Configuration on a computer that is running a product in the Windows Server 2003 family:</P>
|
|
<OL>
|
|
<LI>Open <B>Internet Explorer</B>. </LI>
|
|
|
|
<LI>Click <B>Help</B>. </LI>
|
|
|
|
<LI>Click <B>Enhanced Security Configuration</B>.</LI>
|
|
</OL>
|
|
|
|
<P>The online Help includes instructions for changing the security settings in Internet Explorer. To change these settings, you must log on as a member of the Administrators group on the computer for which you want to change settings.</P>
|
|
|
|
|
|
<H2><A NAME="downloading_software_updates_vvba"></A>Software updates from the Web</H2>
|
|
|
|
<P>Because of changes to default security settings in Internet Explorer, users might not be able to download updates from the Web to their computers. To download updates from the <A HREF="http://go.microsoft.com/fwlink/?LinkId=14265" TARGET="_blank"><U>Microsoft Download Center</U></A>, from the Web sites listed in Microsoft security bulletins, or from other download sites, users might need to add these sites to the Trusted Sites zone in Internet Explorer. If a Group Policy setting prevents users from adding sites to the Trusted Sites zone, administrators might need to configure another Group Policy setting to add the required sites.</P>
|
|
|
|
<P>For more information, see the online Help for Internet Explorer Enhanced Security Configuration as described in the previous note.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="additional_resources_uwuy"></A> Additional Resources</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<P>To review the most recent hardware and application compatibility information and to find other products that Windows supports, see the <A HREF="http://go.microsoft.com/fwlink/?LinkId=3410" TARGET="_blank"><U>Windows Catalog Web site</U></A>.</P>
|
|
|
|
<P>To search for technical support information and self-help tools for Microsoft products, see the <A HREF="http://go.microsoft.com/fwlink/?LinkId=4441" TARGET="_blank"><U>Microsoft Knowledge Base</U></A>.</P>
|
|
|
|
<P>To obtain the latest product updates, see the <A HREF="http://go.microsoft.com/fwlink/?LinkId=284" TARGET="_blank"><U>Windows Update Web site</U></A>.</P>
|
|
|
|
<BR><BR>
|
|
<TABLE border=0 cellPadding=0 cellSpacing=0 width="97%">
|
|
<TBODY>
|
|
<TR vAlign="bottom">
|
|
<TD>
|
|
<H1><A NAME="copyright_gwtm"></A> Copyright</H1>
|
|
</TD>
|
|
<TD align="right"><A class="finePrint" href="#top">Back to Top</A></TD>
|
|
</TR>
|
|
</TBODY></TABLE>
|
|
<HR>
|
|
|
|
<P>Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise noted, the example companies, organizations, products, domain names, e-mail addresses, logos, people, places and events depicted herein are fictitious, and no association with any real company, organization, product, domain name, e-mail address, logo, person, place or event is intended or should be inferred. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation. </P>
|
|
|
|
<P>Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property.</P>
|
|
|
|
<P>© 2003 Microsoft Corporation. All rights reserved.</P>
|
|
|
|
<P>Microsoft, <NOBR>MS-DOS</NOBR>, Windows, Windows NT, Active Directory, and MSN are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.</P>
|
|
|
|
<P>The names of actual companies and products mentioned herein may be the trademarks of their respective owners.</P>
|
|
|
|
</BODY>
|
|
</HTML>
|