Re: CIFS and Windows Server 2003

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Steve Schofield (steve_at_adminblogs.com)
Date: 05/10/04


Date: Mon, 10 May 2004 19:13:38 -0400

ran into the same thing with Novell CIFS, it has something to do with
digital signing in both default domain policies. We changed the following
security policy settings on BOTH of the following:

Default Domain Policy
Default Domain Controllers Policy
1. Start | Programs | Administrative tools
2. Choose Domain Controller Security Policy | Local Policies | Security
Options
3. Change the following:
      Microsoft network server: Digitally sign communications (always)
Value = disabled
      Network security: LAN Manager authentication level value = Send
LM & NTLM - use NTLMc2 session

security if negotiated
4. Close
5. Choose Domain Security Policy | Local Policies | Security Options
6. Change the following:
      Microsoft network server: Digitally sign communications (always)
Value = disabled
      Network security: LAN Manager authentication level value = Send
LM & NTLM - use NTLMc2 session

security if negotiated

Steve Schofield
steve@deviq.com

Microsoft MVP - ASP.NET
http://deviq.com

"Joe Richards [MVP]" <humorexpress@hotmail.com> wrote in message
news:e19eX5fNEHA.3016@tk2msftngp13.phx.gbl...
> Are you using kerberos for the authentication from HPUX? That may be the
issue.
> Windows Server 2003 drops one or more of the more insecure kerberos
mechanisms.
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
>
> faels wrote:
> > We are currently using FacetCorp's FacetWin to access resources on an
> > HPUX platform from Windows.
> >
> > We recently upgraded one of our domain controllers to Windows Server
> > 2003 Standard Edition. Prior to the upgrade, we were successfully
> > using this server to authenticate users trying to access NetBIOS
> > resources on the HPUX box. After the upgrade we started receiving
> > errors when trying to authenticate using the new 2003 DC. Everything
> > seems to work for a few hours before authentication starts to fail.
> >
> > If we point the HPUX box to a Windows 2000 domain controller,
> > everything works just fine.
> >
> > We have disabled all policies requiring SMB signing, and enabled
> > "Sending unencrypted passwords to third party SMB servers" for the
> > domain. I am also supporting all available types of LM and NTLM
> > authentication.
> >
> > I have created SPNs for the Windows services that need access to the
> > Unix resources, trusted the associated machines and services users for
> > delegation, and still can't get it to work.
> >
> > Can anybody tell me why this works on 2000 but not on 2003? Is it a
> > Kerberos issue? If so, is there any sound literature on service
> > principal names and their role in AD?
> >
> > I tried capturing packets, but could not find any useful information.



Relevant Pages

  • Re: DMZ NT4 TO Internal 2000 AD One-Way Trust via Firewall
    ... leverage an effectivity security policy to ensure that password complexities ... > currently a mess of local and domain users, no security policy, etc. ... DMZ, not publicly accessible) that aren't going away within the stated ... to non-DC web servers in the DMZ on 80 and 443 - none of which are directed ...
    (microsoft.public.windows.server.active_directory)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... > Checkpoint propaganda stuff. ... > spent most of my security consulting career trying to stomp out bloated ... >>All NetScreen appliances rely on custom-designed ASICs (Application ... >>Specific Integrated Circuits) for security policy enforcement. ...
    (Firewall-Wizards)
  • Re: Support Sharon Angle
    ... was promoted to Deputy Assistant of Defence for ... International Security Policy by his administration. ... He was a political appointee of the first Bush admin. ...
    (rec.sport.golf)
  • Policy change kills access to template
    ... Policy or Domain Controller Security Policy, local policies, and make ANY ...
    (microsoft.public.win2000.security)
  • Re: Okay.. what is going on here .. Security error?
    ... CAS assigns trust not based upon user credentials, ... against the security policy, and a permission grant is generated. ... you'll need to modify your security ...
    (microsoft.public.dotnet.security)