3s-gtech Posted May 17, 2022 Posted May 17, 2022 Thankfully not the case for us, but definitely something for you to bear in mind. I’m not sure how the cert could renew if it’s being used for the active connection, but I’m not certain on the whole process. Can you do it in a test scenario?
Primus Posted May 18, 2022 Posted May 18, 2022 Interesting - so 1 site the update worked and caused no issues - I am seeing event ID 39 in the logs. At another site the update borked RADIUS as others are seeing and I see event ID 6273. I've temporarily removed the May update for now but need at least a medium term solution that allows the update to happen and then a longer term plan for what needs to be done to comply with their new enhanced requirements for certs.
k-strider Posted May 18, 2022 Posted May 18, 2022 My WiFi broke last week because of it, was set to authenticate as Smartcard or other certificate. Had to do a new NPS Rule and a new GPO profile to make it use Microsoft Protected PEP to make it work and go around all my machines and GPUpdate them to use the new config. ours is already set to PEAP not Smart card or other i wonder if the clients update caused this cause our clients are auto install but servers havent been done yet and we havent seen this issue here and we will have had clients by now with the may updates on.
jthompson Posted May 18, 2022 Posted May 18, 2022 ours is already set to PEAP not Smart card or other i wonder if the clients update caused this cause our clients are auto install but servers havent been done yet and we havent seen this issue here and we will have had clients by now with the may updates on. Interesting. I did think along those lines for a bit, and wondered also about whether another factor was the GPOs we have in place which disable LLMNR, TLS 1.0 and TLS 1.1, and whether that was somehow involved in breaking something. I also thought "it's probably going to end up being DNS", but couldn't see any DNS issues.
mullet_man Posted May 21, 2022 Posted May 21, 2022 I applied the May updates last night and so far not seeing any problems in NPS or any warning events being logged. I had the patch with the fix on standby but looks like I didn't need it here.
free780 Posted May 21, 2022 Author Posted May 21, 2022 There are quite a few variables here. It’s possible to setup a Always On VPN with RRAS that doesn’t use NPS if certificate based. If the VPN Server isn’t domain joined I’m assuming the additional checks won’t be done. A trusted certificate has to be provisioned and trusted by the VPN Server and the client. However forwarding the requests to a NPS server where PEAP/EAP occurs may encounter issues where the SID can’t be verified. Given the vulnerability additional verification is probably wise. I’m not sure of the impact on 802.1x. Microsoft need to provide more details. With the original May update errors would only be logged and access still given. Many Reddit comments seem to indicate that the new events don’t get logged with the original May update.
LeMarchand Posted May 26, 2022 Posted May 26, 2022 Have recently had problems across two sites where drives are intermittently not being mapped at startup and one site had time sync errors preventing logon today. Could this be connected, or should I start a new thread?
jthompson Posted May 27, 2022 Posted May 27, 2022 Sounds like a DNS issue, so most likely unrelated. 1
Theldron Posted June 9, 2022 Posted June 9, 2022 Just had 4 days of nightmares because of this update. Had no wifi in one school and patchy wifi that kept dropping out at another school. None of the actual warning signs listed by Microsoft were present in the environments and the affected services have been completely different. But the out of bands patch for this update fixed both schools.
k-strider Posted June 15, 2022 Posted June 15, 2022 i didn't patch my DCs or Certificate server in May and wondering if the May 19, 2022—KB5015019 (OS Build 14393.5127) Out-of-band has been rolled into Junes Updates.... not sure im feeling brave enough to patch them as about to fly USA for a few weeks :-/
colly72 Posted June 16, 2022 Posted June 16, 2022 i didn't patch my DCs or Certificate server in May and wondering if the May 19, 2022—KB5015019 (OS Build 14393.5127) Out-of-band has been rolled into Junes Updates.... not sure im feeling brave enough to patch them as about to fly USA for a few weeks :-/ Yes, the June updates patch that issue, even if you haven't applied the May Out of band update: https://support.microsoft.com/en-us/topic/june-14-2022-kb5014699-os-builds-19042-1766-19043-1766-and-19044-1766-5c81d49d-0b6e-4808-9485-1f54e5d1bb15
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now