Re: Disabled administrative shares?

From: Kevin Longley (kwlongley_at_cirtronics.com)
Date: 07/23/04


Date: Fri, 23 Jul 2004 19:19:42 -0400

This may be the issue:

 Down level client compatibiolity - To prevent domain controllers
from requiring secure channel signing or encryption Open Active
Directory Users and Computers. In the console tree, right-click Domain
Controllers, click Properties, and then click the Group Policy tab.
Click Default Domain Controllers Policy, and then click Edit. Under
Security Options, right-click Domain member: Digitally encrypt or sign
secure channel data (always), click Properties, and then click Disabled.
Where?

*Computer Configuration
* Windows Settings
* Security Settings
* Local Policies
* Security Options

By disabling this security setting, you expose secure channel
communications to man-in-the-middle attacks.

"Sysadmin" <anonymous@discussions.microsoft.com> wrote in message
news:300401c470dd$429b16c0$a301280a@phx.gbl...
> Hi everybody:
> We had one single DC W2K based, we added a second DC 2K3
> based and after that some rare things happened to our
> W98SE boxes, these machines does not allow connection to
> administrative shares, even if your're connecting like
> domain or enterprise admin.
> Thanks for any help.
>
>



Relevant Pages

  • Re: Cant log on to a Win2k3 domain with a DOS client
    ... Open Active Directory Users and Computers. ... In the console tree, right-click Domain Controllers, click Properties, and ... secure channel data, click Properties, and then click Disabled. ... > have a domain controller for about 5-10 fat clients we have around. ...
    (microsoft.public.windows.server.general)
  • Re: Mapping
    ... The following settings are required if you are supporting win9x computers. ... To prevent domain controllers from requiring secure channel signing or ... In the console tree, right-click Domain Controllers, ... Digitally encrypt or sign secure channel data ...
    (microsoft.public.windows.server.general)
  • Re: Domain Local group and Require strong. GPO Problem
    ... Microsoft MVP (Windows Server System: ... >> controller that is not capable of encrypting secure channel traffic with ... >> that all such domain controllers must be running Windows 2000 or later ... >> Session keys used to establish secure channel communications between ...
    (microsoft.public.win2000.security)
  • Re: Domain Local group and Require strong. GPO Problem
    ... > setting determines whether a secure channel can be established with a domain ... > Session keys used to establish secure channel communications between domain ... Disabling this ... > this option if the domain controllers in all trusted domains support strong ...
    (microsoft.public.win2000.security)
  • Re: How to change secure identifier request interval?
    ... > days on a 2000/XP system) is the password used to setup a secure channel ... > between the workstation and the domain controllers. ...
    (microsoft.public.win2000.networking)