HPlum78 Posted May 13, 2022 Posted May 13, 2022 After installing updates released May 10, 2022 on domain controllers, you might see authentication failures on the server or client for some services. These services include Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP). An issue has been found related to how the domain controller manages the mapping of certificates to machine accounts. Note Installation of the May 10, 2022 updates on client Windows devices and non-domain controller Windows Servers will not cause this issue. This issue only affects servers that are used as domain controllers. The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping. Note The instructions are the same for mapping certificates to user or machine accounts in Active Directory. If the preferred mitigation will not work in your environment, see KB5014754—Certificate-based authentication changes on Windows domain controllers for other possible mitigations in the "SChannel registry key" section. Note Any other mitigation except the preferred mitigations might lower or disable security hardening. The above is from the support page worth being aware of. 3
free780 Posted May 13, 2022 Posted May 13, 2022 Useful links in this thread. May 2022 Windows Updates may cause issues with NPS and RRAS https://www.edugeek.net/showthread.php?t=227690 1
Primus Posted May 13, 2022 Posted May 13, 2022 Has anyone installed them and not had issues? - I'm wary of Microsoft's "may".
Popular Post Koldov Posted May 13, 2022 Popular Post Posted May 13, 2022 I'm wary of Microsoft. FTFY.... 6
HPlum78 Posted May 13, 2022 Author Posted May 13, 2022 Yeah I love the MAY MIGHT statement an all! Lots of scope in those words.... makes a mess of DEV TEST LIVE
free780 Posted May 17, 2022 Posted May 17, 2022 I’d wait until the issue is marked as resolved or mitigated on the Windows Release Health.
Koldov Posted May 18, 2022 Posted May 18, 2022 Will it be though? It already seems like there is a 'preferred' mitigation in place. "The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping." https://support.microsoft.com/en-us/topic/may-10-2022-kb5013952-os-build-14393-5125-0bb9f7e6-0360-4162-8eab-108e28d3a090#:~:text=Known%20issues%20in%20this%20update Is this not like 'Print Nightmare' then, where they've made the change and that's just how it is now... or is it definitely an bug/error that they will 'fix'...?
free780 Posted May 18, 2022 Posted May 18, 2022 Still "Investigating" for Server 2016. https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-1607-and-windows-server-2016#2826msgdesc
mullet_man Posted May 18, 2022 Posted May 18, 2022 Will it be though? It already seems like there is a 'preferred' mitigation in place. "The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping." https://support.microsoft.com/en-us/topic/may-10-2022-kb5013952-os-build-14393-5125-0bb9f7e6-0360-4162-8eab-108e28d3a090#:~:text=Known%20issues%20in%20this%20update Is this not like 'Print Nightmare' then, where they've made the change and that's just how it is now... or is it definitely an bug/error that they will 'fix'...? There's a big reddit post about this update and a lot of admins seem to suggest the reg fixes don't work. Am going to hold off applying the updates as it could potentially break wireless for us.
SpaceInvader83 Posted May 18, 2022 Posted May 18, 2022 CISA are advising not to install, I'm hanging fire for now. 1
SpaceInvader83 Posted May 20, 2022 Posted May 20, 2022 Looks like it's been sorted (Apparently) https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019 1
Ertech Posted May 20, 2022 Posted May 20, 2022 Has anyone been able to test Microsoft's emergency updates fix? https://www.bleepingcomputer.com/news/microsoft/microsoft-emergency-updates-fix-windows-ad-authentication-issues/
Primus Posted May 20, 2022 Posted May 20, 2022 Has anyone been able to test Microsoft's emergency updates fix? https://www.bleepingcomputer.com/news/microsoft/microsoft-emergency-updates-fix-windows-ad-authentication-issues/ I'm trying it now.
chris11256 Posted May 20, 2022 Posted May 20, 2022 Thanks for the headsup, I'll hold off installing for a few more days then.
Michael Posted May 20, 2022 Posted May 20, 2022 So out of curiosity, has anyone installed the May 2022 CU and the May OOB patch on either 2016 or 2019 DCs? I'm still on the April 2022 CU for all servers.
Primus Posted May 20, 2022 Posted May 20, 2022 Ours are 2019, that fix patch didn't work. We'll look at it again during half term, it's too disruptive to mess with again for now.
free780 Posted May 20, 2022 Posted May 20, 2022 2016 DCs in a test environment. No issue with cert auth with KB5013952. I'm going to apply the new "fixed" update KB5015019 and test. My VPN Server is not on the domain. Using Computer Level Certs.
Ertech Posted May 23, 2022 Posted May 23, 2022 (edited) Btw is it only the DCs that are getting affected by the May update? Would it be OK to apply the May updates on all other servers and leaving the DCs out? Edited May 23, 2022 by Ertech
Steve21 Posted May 23, 2022 Posted May 23, 2022 (edited) Btw is it only the DCs that are getting affected by the May update? Would it be OK to apply the May updates on all other servers and leaving the DCs out? There's an out of band to resolve the DC issues now anyway, so no harm in installing. Just needs the manual update applied after https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015019-os-build-14393-5127-out-of-band-8548dfda-38ba-4fb6-a7a3-42b86ac2cc81 https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015018-os-build-17763-2931-out-of-band-e4c28a4d-7dbe-4ef5-a539-f0b21cba2ebb etc depending on which OS (Edit - As a side note, as noticed someone above said about NPS still, it seems to depend on the order you install the updates to whether it resolves it. Regarding updating the CA first for PKI, resetting OID etc) Steve Edited May 23, 2022 by Steve21
Ertech Posted May 23, 2022 Posted May 23, 2022 There's an out of band to resolve the DC issues now anyway, so no harm in installing. Just needs the manual update applied after https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015019-os-build-14393-5127-out-of-band-8548dfda-38ba-4fb6-a7a3-42b86ac2cc81 https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015018-os-build-17763-2931-out-of-band-e4c28a4d-7dbe-4ef5-a539-f0b21cba2ebb etc depending on which OS Steve Do just apply the out of band updates manually on the DCs after installing the May updates? - no need to apply out of band updates on any other server?
Michael Posted May 23, 2022 Posted May 23, 2022 Do just apply the out of band updates manually on the DCs after installing the May updates? - no need to apply out of band updates on any other server? Yes - but they're only available on the Windows Catalog and not Windows Update. All a manual process and only applies to DCs. I'm half tempted to skip the May update on DCs and install the June update when it becomes available.
mullet_man Posted May 23, 2022 Posted May 23, 2022 So out of curiosity, has anyone installed the May 2022 CU and the May OOB patch on either 2016 or 2019 DCs? I'm still on the April 2022 CU for all servers. Installed the May 2022 CU on 2016 3 DCs and 1 CA server, so far no problems. We use NPS and computer certificate for wireless connections. Cant see any errors at all. Cheers.
Ertech Posted June 28, 2022 Posted June 28, 2022 (edited) Has anyone applied the June updates? Any problems with it? Edited June 28, 2022 by Ertech
3s-gtech Posted June 28, 2022 Posted June 28, 2022 I've skipped May and went to the June updates instead, installed over the weekend. Our AoVPN/NPS/RADIUS/CA all seem to be working, but not extensively tested all services. We don't use certs with our internal wifi which I know was one issue identified. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now