Coder, of course I understand there are
people using their old "Closet Computers"
as X10 controllers. I even said so in a
post you must have skipped. That has
nothing to do with whether they should use
them as Internet facing web servers. Flat
out, if they're running a non-secure OS
they shouldn't. Period. And no reasonable
company should tell them to if their own
reputation was on the line.
As for your "I wouldn't run IIS" statement.
Well, given that most of the large websites
on the planet including most of the e-
commerce sites run it. I'm guessing your
opinion isn't that valid. But, feel free to
add on an extra web server that requires an
extra authentication and authorization
system and then make sure you configure all
three (OS, Apache and typically Kerberos)
correctly. I'm sure after checking with all
the sites involved you'll never miss out on
a configuration change needed for security.
I, on the other hand, will tell Windows
Server 2003 that I'm running a web server
and it'll do most of the base
configuration. Then I'll let Windows Update
keep the entire system updated for me. (And
running at 99.999% uptime if I spend the
money for good, certified hardware)