Windows XP
1. Windows XP
Windows XP Professional . , - . Windows XP Professional , : , EFS (Encrypting File System), .
, . Windows XP Professional . , - . Windows 2000 - Kerberos 5. Windows NT 4.0 Windows NT Windows XP Professional NTLM. Windows XP Professional, , NTLM. Windows XP Professional (Active Directory), , , . , . , . .
. (access control list, ACL) NTFS , , , , ( ), . , , , .
. , . . MMC Computer Management . , . . , , . , , , .
(Administrators) . Windows XP Professional (Administrator). , (Domain Administrators).
(Power Users) , . . , (Users) (Power Users) Windows NT 4.0.
(Users) . . ( ), , , . Windows XP Professional Windows NT 4.0.
(Guests) Guest , . , , , ( ), Guest. , Guests. Guest . (ACL) / , . ACL. , . ; . Windows XP Professional , . Windows XP Professional , .
, . , ( , , ) . , , , , Active Directory. . , . - , (Active Directory). .
EFS (Encrypting File System) . , EFS . .
2.
Windows XP Professional , . (ACL), , . , . Windows XP , . Windows XP , . : , ; ACL ; , Users, Power Users Administrators, ACL; - Basic (), Compatible (), Secure () Highly Secure (). Windows XP - ACL, - , . . , Microsoft Management Console, Windows XP Professional, Windows XP Professional Resource Kit.
3.
Windows XP . , . , .
Windows XP Professional , . ( , ) . , , . Windows XP Professional , , Guest. (Administrator), .
4.
(Guest) (Classic) . . . , . , , Guest. "force network logons using local accounts to authenticate as Guest" Guest . , . , , , Security Properties Shared Documents Properties.
5.
, , Windows XP Professional . , . , (RunAs - ) . , , . , . , , , . , . , . Guest , , . , (Local Security Policy).
(Encrypting File System, EFS) Windows XP Professional, , . , , , . EFS . , . . , - (Take Ownership), . , . .
EFS
EFS CryptoAPI. ( ) EFS : . EFS , . EFS DESX (Expanded Data Encryption Standard) 3DES (Triple-DES). : RSA Base RSA Enhanced - EFS . , . , .
EFS NTFS
(EFS) NTFS. EFS - NTFS. , . : , . Windows XP (Offline Files and Folders). , , , . EFS NTFS. EFS Windows XP Professional , .
EFS
EFS , , , . EFS , , . . , , ACL. , . , , . , EFS . EFS NTFS, ("") . EFS , - . , , ( , ). EFS Windows - . - .
EFS
EFS. , . EFS , / . EFS , , . EFS , , EFS . EFS EFS. (Public Key Infrastructure, PKI), , . EFS . EFS, .
NTFS ( ). "", , . EFS : , ; , ; ( ); .
Windows XP , . Windows 2000 - . , , . , . - . . . , (My Computer) (Tools) (Folder Options), (Offline Files) (Encrypt Offline Files To Secure Data) .
EFS Web-
, Web- Web Distributed Authoring and Versioning ( Web), WebDAV. Web- , Microsoft . Web- , . Web- HTTP. EFS, Windows 2000 Windows, EFS Kerberos. EFS Web- - , . , EFS , . , , , , . Web- EFS . , Web- EFS. Web- - , , , . EFS , , Web-. EFS Web- . EFS.
6.
- , (certification authority, CA), , . Windows XP Professional , .
Windows XP Professional (Personal) . , . . Documents and Settings\<_>\ApplicationData\Microsoft\ SystemCertificates\My\Certificates . . ( ) "" .
(cryptographic service provider, CSP) - Base CSP, Enhanced CSP, %SystemRoot%\Documents and Settings\<_>\ Application Data\Microsoft\Crypto\RSA. RSA . , RSA - (user's master key). 64 . 3DES, . . Triple DES , . RSA .
Windows 2000 . Microsoft Active Directory. IPSec L2TP/IPSec VPN Windows XP Routing Remote Access . . - , .
Windows XP Professional . Windows .NET Server CA . . . , Active Directory. . , .
7.
Windows XP : , (keyring).
, . ( , .) X.509 My Store. Remember my password ( ), . Windows XP (, Kerberos, NTLM, SSL). , .
Stored User Names and Passwords ( ). (Local Security Settings). , . Remember my password , . , *.domain.com. , . , . , . , , . , , . , . . Windows XP Professional , Windows XP Home Edition Windows XP Professional - .
(keyring) . User Accounts . . . , . , , . (*). . . , . , . . . , API API Platform Software Development Kit (SDK).
8.
Windows XP Professional , . , , . Windows XP Professional, , . , , Microsoft Windows 2000 Terminal Services. " " +L . , , , - , . Windows , , , .
, , , , 2 . 128 . , , - , ! "" (hibernation mode) , . Windows XP Home Edition Windows XP Professional . Windows XP Professional .
9.
Windows XP Professional , Windows XP Home Edition. . .
10. - Internet Connection Firewall
Internet Connection Firewall Windows XP Professional - , DSL.
ICF
ICF Windows XP Professional - . , : , . . Windows XP Professional , , ICF . , . , ICF , .
, , ICF ICS. ICF , . ICF . ICF Network Address Translation (NAT) . NAT, . , , . ICF Windows XP Professional , . : . ICF Windows XP Professional , . ICF , .
,
Windows XP , , . : (low), (medium) (high). : ; ; .
9.
, . , "", , . , , Microsoft Authenticode . , . -, "". , , -, ILOVEYOU.VBS, . , . . Active Directory. . Windows XP Windows 2000. Windows 2000- , Windows XP . Group Policy Microsoft Management Console (MMC) , , . : unrestricted ("") disallowed (""). unrestricted, , . . , . - ( disallowed), , .
11. IPSec
IP- - , , . , : ; , ; ( ) ; ( ). , , .
IPSec
IP , IP- , , , . , . - . . , . Internet Engineering Task Force (IETF) IPSec - , , . IPSec Windows 2000 Windows XP Professional. , - . TCP/IP . Windows 2000 Windows XP Professional , . IP- , , . IPSec Windows XP Professional Windows 2000 , , IPSec, .
IPSec . . . - , - , , . IPSec . Windows 2000 Windows XP Professional.
IPSec
IPSec , . , , ( ) ( ). , . . . ( ) IP- . , Windows XP Professional , IPSec, . , Windows 2000-, , .
12. -
- - , , . , , . - : ; , , , , ; , .
PIN
- PIN- (Personal Identification Number - ), . -, . - PIN-. PIN- . ( , , ) . , , . , PIN- , . - - PIN-, . - .
-
Windows 2000 - -, PC/SC (Personal Computer/Smart Card), PC/SC Workgroup, Plug and Play. PC/SC 1.0 Windows - ISO 7816-1, 7816-2 7816-3. - , RS-232, PS/2, PCMCIA USB. - RS-232 , PS/2 . PS/2- , . - Windows PnP-. Windows Hardware wizard. Windows 2000 Server Windows XP Professional PnP- - Windows. , Windows. Microsoft -, Windows.
-
- , . Windows 2000 Server Windows XP Professional , Kerberos v5. - Kerberos v5 X.509 v3, Windows 2000 Server. -, , . -. , .
-
, . , Net.exe Runas.exe, . Windows XP Professional -.
13. Kerberos v5
Windows 2000 Windows XP Professional , Kerberos - ( -). Kerberos v5 (, , ) . Kerberos v5 . Kerberos , , . . , , . Kerberos v5 . Kerberos v5 () . . Kerberos, Active Directory.
- (, ), , . KDC . KDC, TGT (ticket-granting ticket), (Local Security Authority, LSA) . , , . - "" , ("") .
Kerberos
Kerberos Active Directory. Kerberos v5 Windows 2000 Server Windows XP Professional , , , Windows 2000 Windows XP Professional. , NTLM.