Re: Effect of "reversible encryption..." on Windows XP.

From: Gordon Fecyk (gordonf_at_pan-am.ca)
Date: 03/10/05


Date: Thu, 10 Mar 2005 09:12:33 -0600


> I enabled it on my XP box using gpedit.msc and verfied using rsop.msc that
> in the effective settings it is enabled. However, I fond that the password
> hash present in registry is same irrespective of this setting. I also
tried
> creating new users after enabling/disabling the policy to check if the
effect
> is only on new users. I found that it has no effect what so ever on the
way
> passwords are stored internally in registry.

Don't you have to change the password after enabling this policy? Changing
the policy wouldn't have an effect on existing stored passwords, or admins
would have a hard time staying logged on after changing the policy.

-- 
PGP key (0x0AFA039E): <http://www.pan-am.ca/consulting@pan-am.ca.asc>
Prevent problems before they happen and help others avoid bad design.
<http://www.pan-am.ca/antiwindowscatalog/>


Relevant Pages

  • Re: GPO Replication to DMZ
    ... communicate with the domain controller in order for any Local Security ... Policy changes to be effective to make sure that no domain/OU settings will ... Effective settings never get set on the ... Local Security Policies never become active. ...
    (microsoft.public.win2000.security)
  • Re: Machine policy when user logged onto local machine
    ... Interesting point about effective settings. ... NB most of the time I'm logged in on a local machine account, ... had just been rebooting the client to force it to take the new policy. ... I've disabled the security policy for the moment until I've got a better ...
    (microsoft.public.win2000.security)
  • Re: deny logon locally for other domain users
    ... I believe the actual problem is in effective settings of the policy. ... Since domain policies override local ... > who I want to deny to login. ...
    (microsoft.public.win2000.networking)
  • Re: shutdown permissions
    ... It should work as you described then, especially if effective settings show the ... If you have an XP Pro machine in the domain you can use the ... Group Policy Management Console on it to manage W2K domain policy ... The 2 rights were left as not defined. ...
    (microsoft.public.win2000.security)
  • Re: What program is used to write events to the event log??????
    ... The intent of Safer is for it to be applied from AD in GPOs. ... that they are refteshed by the sce policy engine. ... > registry files is that while apparently the restrictions are aplied...you ... >>> issue....whenever there is an exe being started it normally writes this ...
    (microsoft.public.windowsxp.security_admin)