To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain controllers

From: Murad Talukdar (talukdar_m_at_subway.com)
Date: 05/03/05

  • Next message: Soluk, Kirk: "RE: To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain controllers"
    Date: Tue, 03 May 2005 17:31:30 +1000
    To: focus-ms@securityfocus.com
    
    

    Hi All,
    We have had arrival of new scanner/printer/copier in office. It uses SMB to
    scan files to shared folders on our W2003 network. In order for it to work
    however, I have had to do the following;

    1. From Administrative Tools open Domain Controller Security Policy 2. Smile
    3. Select \Security Settings\Local Policies\Security Options folder. 4. In
    the details pane, double-click Microsoft network server: Digitally sign
    communications (always), and then click Disabled to prevent SMB packet
    signing from being required. 5. Click OK. 6. In the details pane,
    double-click Domain member: Digitally encrypt or sign secure channel data
    (always), and then click Disabled to prevent secure channel signing from
    being required. 7. Click OK.

    Before that, the scan would fail to be sent to the server in question.
    What are the implications of this--given that we do not ostensibly use SMB
    for anything else.
    I've heard scare stories of SMB man in the middle attacks and was under the
    impression that this is what these specific security settings were
    pertaining to but am not sure.

    There are other options for the scanning ie ftp/email but neither would work
    as we cannot get approval for cost of ftp server nor can the email system
    take the file sizes that are often req'd by scans our users make.

    I can see there will be advice against having shared user folders etc on
    DC's too but the big boss wants more from less if you see what I mean.

    Kind Regards
    Murad Talukdar

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Soluk, Kirk: "RE: To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain controllers"

    Relevant Pages

    • Re: Networking to specific users
      ... >>>network to my old user name's files on the desktop computer, ... If I share my folders everyone that uses the desktop computer will ... Windows XP doesn't have passwords for shared folders, ...
      (microsoft.public.windowsxp.network_web)
    • Re: Networking to specific users
      ... is there a way to put folders in the Shared Documents ... that also prevents it from being shared over a network. ... > If your desktop computer has Windows XP Professional, ... > access to shared folders by creating a network password for the Guest ...
      (microsoft.public.windowsxp.network_web)
    • Re: Workgroup Not Accessible
      ... > I noticed I was no longer on my network. ... > on my workgroup, nor their shared folders, and I can't see my own shared ... The other 3 computers were still fine ... > shared folders of the workgroup computers. ...
      (microsoft.public.windowsxp.network_web)
    • Re: Access to XP shared folders
      ... The shared folders I'm trying to browse are on the local machine ... itself not a machine located on the network. ... I can only get to any of these shares when TestXP is ... >>my folders both when I'm connected and disconnected from the domain. ...
      (microsoft.public.windowsxp.network_web)
    • Re: Guest account
      ... folders and set up a VPN connection between the 2 machines. ... >>shared folders from a few pc's on the network. ... Use Compressed Folders in Windows XP ...
      (microsoft.public.windowsxp.network_web)

  • Quantcast