Jump to content

Recommended Posts

Posted (edited)

I've just come across this issue today too, however when connecting to our internal 2012 servers. Is there a fix that can be done on the server for this?

 

It appears the info from MS is lacking here, however this been a security fix I'd rather leave it installed and fix what's wrong on the server.

 

Cheers

 

edit:

KB4103721 has the fix included.

Edited by gtg93
Posted

Does anyone have any more info on what is up with this KB in general?

 

I am seeing WSUS reporting it is failing on a lot of my Windows 7 machines...

 

It also leads to a black screen on a very old Win 7 machine that we use to loop a PowerPoint in the ICT room.

Posted
Interesting, a lot of us in the office have started seeing this a lot connecting to any servers - all running Windows 10 and the latest updated we've had is KB4103729.
Posted
Interesting, a lot of us in the office have started seeing this a lot connecting to any servers - all running Windows 10 and the latest updated we've had is KB4103729.

 

 

For info, found a fix on another sauce. Adding the below key to the registry fixes the problem:

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters] "AllowEncryptionOracle"=dword:00000002

Posted
Interesting, a lot of us in the office have started seeing this a lot connecting to any servers - all running Windows 10 and the latest updated we've had is KB4103729.

 

It seems different versions of Windows 10 have a different KB No. for the update. Once the servers is fully up to date it should fix the issue without the need for the reg fix - obviously, not easy to down the server for everyone or when hosted by someone else in the case of hosted sims!

Posted

This is affecting more than just RDP connections.

The latest update appears to have stopped SHA1 from being negotiated completely.

I’ve had all sorts of issues with connections with VPN clients.

 

Certainly with SonicWall VPN clients stored credentials are being used that can no longer be negotiated.

Domain\username no longer works but user@domain does.

Evidently all servers performing AD auth must be updated.

 

Admins all over the world are suddenly finding themselves unable to login to servers using RDP/RDS from Windows unless the servers are updated.

 

This Registry Mod IS NOT A FIX it’s a FUDGE it only forces the clients OS to ask for a lower level of server/host connection rather than the one being requested after the latest update.

  • Thanks 1
Posted

It does seem like MS has clusters of servers for everything. They can update them in an automated fashion with no down time. They probably have automations to rebuild servers if an update breaks them

Not so in the real world. Usually the client OS is patched first. Shame they couldn't have included the registry setting in the update and then switch it next month.

  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...