Determine Your Need for Server Core

10/9/2010 3:56:11 PM

Server Core is a new feature in the Windows Server world. It installs a command-line administration-only version of Windows Server 2008 that helps reduce the attack surface of the server. Traditionally, there are many attack options on a Microsoft server, and you, the administrator, need to be aware of that and take action to ensure security. However, with Server Core, less code is installed (that is, there is a smaller footprint), and with that reduction in code comes a reduction in the number of places an attacker can hit. Fewer moving parts equals fewer vulnerabilities.


What is the attack surface area of an operating system? Keep in mind that each application added to a system provides a corresponding opportunity for attack and so poses a risk. In addition, certain services may leave your system open to infiltration. This is all considered the attack surface, and the goal in securing a system is to reduce that surface, typically by turning off or removing features that are unnecessary.

Until you see a Server Core system for yourself, you may not believe that you are really going to be working from a command prompt again. But that is truly what you have at your disposal. In fact, the Explorer shell is not even installed. You may be surprised to learn that you aren’t working with the new PowerShell command prompt.

PS Note

At the time of this writing, PowerShell was not functional in Server Core because it requires the .NET Framework, which cannot be installed on a Server Core system at this time. The .NET team has worked on providing a modularized version for Server Core admins to be able to work with PowerShell, and this will be available in R2. See the section “Incorporate Server Core Changes in Server 2008 R2,” later in this chapter.

Now, keep in mind that Server Core isn’t able to provide all the server roles that a typical server would have. The supported roles in Server Core include the following:

  • Active Directory Domain Services (ADDS)

  • Active Directory Lightweight Directory Services (AD LDS)

  • DHCP Server

  • DNS Server

  • File Services

  • Internet Information Services (IIS)

  • Print Services

  • Streaming Media Services

  • Windows Virtualization (Hyper-V)

And, as you will soon see, you cannot use the Server Manager tool to install these roles. Instead, you need to install them through the command line, using a tool called ocsetup.exe.

Keep in mind that third-party application software cannot typically be installed and managed on a Server Core server, so this server isn’t going to be used for things like your antivirus management or even some of the management solutions that Microsoft provides that must be installed on top of the server and require certain underlying services to be running. What this is a good fit for in an environment, however, is in areas like DNS or DHCP services or even file services.


Although IIS is installable on Server Core, Server Core doesn’t currently support ASP.NET. Due to the lack of support for managed code, there are many reasons you might not be able to use Server Core for your particular web server (for example, no IIS-ASPNET, IIS-NetFxExtensibility, IIS-ManagementConsole, IIS-ManagementService, IIS-LegacySnapIn, IIS-FTPManagement, WAS-NetFxEnvironment, and WAS-ConfigurationAPI).

  •  Install Windows Server 2008
  •  Windows Server 2008 : Configure NAP
  •  Incorporate Server Core Changes in Windows Server 2008 R2
  •  Decide What Edition of Windows Server 2008 to Install
  •  Perform Other Pre-Installation Tasks
  •  Developing Windows Azure Services that Use SQL Azure
  •  Creating Windows with Mixed Content
  •  Mixing Windows and Forms
  •  Exploring an Assembly Using ildasm.exe
  •  The Assembly/Namespace/Type Distinction
  •  Communicate Between Two Machines on the Same Network (WCF)
  •  Communicate Between Processes on the Same Machine (WCF)
  •  Create a TCP/IP Client and Server
  •  Get Network Card Information
  •  Store Data when Your App Has Restricted Permissions
  •  Serialize to an In-Memory Stream
  •  Get the Paths to My Documents, My Pictures, Etc.
  •  Watch for File System Changes
  •  Manipulate File Paths
  •  Search for a File or Directory
    Top 10
    Windows 7 : The Zune PC Software (part 4) - Using Zune - Working with Videos, Organizing Pictures
    Windows 7 : The Zune PC Software (part 3) - Using Zune - Rating Content, Working with Playlists
    Windows 7 : The Zune PC Software (part 2) - Using Zune - The Zune User Experience, Enjoying Music
    Windows 7 : The Zune PC Software (part 1) - Finding and Installing Zune, Configuring the Zune Software
    Windows 7 : Microsoft Zune - A Digital Media Alternative - Why Zune?
    Microsoft .NET : Design Principles and Patterns - Applying Requirements by Design (part 2) - Security
    Microsoft .NET : Design Principles and Patterns - Applying Requirements by Design (part 1) - Testability
    Silverlight Recipes : Controls - Applying Custom Templates to a DataGrid Cell
    Silverlight Recipes : Controls - Displaying Row Details in a DataGrid
    Experience Sennheiser HD700 Headphones
    Most View
    The Best Entry Level Phones – November 2012 (Part 5)
    Amazon Isn’t Just For Books Anymore...
    Windows Server 2008 : The Discovery Phase - Understanding the Existing Environment
    System Center Configuration Manager 2007 : Configuration Manager Solution Design - Testing, Stabilizing During the Pilot, Deploying
    Apple Macbook Air 11-inch (MID-2012) - Smallest And Cutest Mac Portable Ever Made
    The Benefits Of A Technet Subscription (Part 2)
    Reference 3A Episode Loudspeaker
    Programming with DirectX : Game Math - Bounding Geometry (part 2) - Bounding Spheres & Bounding Hierarchies
    HTC Sensation XL: Not a simple update
    Panasonic Lumix GX-5
    This Month Highlight – November 2012 (Part 1)
    Rise Of The Mobile Processors (Part 3)
    Corsair SSD Accelerator 45GB - Boost Your System's Performance
    Collaborating via Web-Based Communication Tools : Evaluating Web Conferencing Tools
    Droid Support - Worried About Security Issues (Part 1)
    Something You Should Know About Iphone 5 (Part 2)
    Windows Server 2003 : Windows Terminal Services - Installing an Application, Configuring Terminal Services Licensing
    Upgrade Your Apps (Part 2) - January 2013
    iphone 3D Programming : Optimizing - Lighting Optimizations, Texturing Optimizations, Culling and Clipping
    À La Mode Accessories