RDP authentication CredSSP Encryption Oracle Remediation patch
RDP authentication error
CredSSP Encryption Oracle Remediation patch
Policy path: Computer Configuration -> Administrative Templates -> System -> Credentials Delegation
Setting name: Encryption Oracle Remediation > Vulnerable
Setting name: Encryption Oracle Remediation > Vulnerable
The Encryption Oracle Remediation Group Policy supports the following three options, which should be applied to clients and servers:
Policy setting
|
Registry value
|
Client behavior
|
Server behavior
|
Force updated clients
|
0
|
Client applications that use CredSSP will not be able to fall back to insecure versions.
|
Services using CredSSP will not acceptunpatched clients.
Note This setting should not be deployed until all Windows and third-party CredSSP clients support the newest CredSSP version. |
Mitigated
|
1
|
Client applications that use CredSSP will not be able to fall back to insecure versions.
|
Services that use CredSSP will accept unpatched clients.
|
Vulnerable
|
2*
|
Client applications that use CredSSP willexpose remote servers to attacks by supporting fallback to insecure versions.
|
Services that use CredSSP will accept unpatched clients.
|
Comments
Post a Comment