Jump to content

Recommended Posts

Posted

After installing updates released May 10, 2022 on domain controllers, you might see authentication failures on the server or client for some services. These services include Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP). An issue has been found related to how the domain controller manages the mapping of certificates to machine accounts.

 

Note Installation of the May 10, 2022 updates on client Windows devices and non-domain controller Windows Servers will not cause this issue. This issue only affects servers that are used as domain controllers.

 

The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping.

 

Note The instructions are the same for mapping certificates to user or machine accounts in Active Directory. If the preferred mitigation will not work in your environment, see KB5014754—Certificate-based authentication changes on Windows domain controllers for other possible mitigations in the "SChannel registry key" section.

 

Note Any other mitigation except the preferred mitigations might lower or disable security hardening.

 

The above is from the support page worth being aware of.

  • Thanks 3
Posted

Will it be though? It already seems like there is a 'preferred' mitigation in place.

 

"The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping."

 

https://support.microsoft.com/en-us/topic/may-10-2022-kb5013952-os-build-14393-5125-0bb9f7e6-0360-4162-8eab-108e28d3a090#:~:text=Known%20issues%20in%20this%20update

 

Is this not like 'Print Nightmare' then, where they've made the change and that's just how it is now... or is it definitely an bug/error that they will 'fix'...?

Posted
Will it be though? It already seems like there is a 'preferred' mitigation in place.

 

"The preferred mitigation for this issue is to manually map certificates to a machine account in Active Directory. For instructions, see Certificate mapping."

 

https://support.microsoft.com/en-us/topic/may-10-2022-kb5013952-os-build-14393-5125-0bb9f7e6-0360-4162-8eab-108e28d3a090#:~:text=Known%20issues%20in%20this%20update

 

Is this not like 'Print Nightmare' then, where they've made the change and that's just how it is now... or is it definitely an bug/error that they will 'fix'...?

 

There's a big reddit post about this update and a lot of admins seem to suggest the reg fixes don't work. Am going to hold off applying the updates as it could potentially break wireless for us.

 

Posted
So out of curiosity, has anyone installed the May 2022 CU and the May OOB patch on either 2016 or 2019 DCs? I'm still on the April 2022 CU for all servers.
Posted

Ours are 2019, that fix patch didn't work.

 

We'll look at it again during half term, it's too disruptive to mess with again for now.

Posted

2016 DCs in a test environment. No issue with cert auth with KB5013952.

 

I'm going to apply the new "fixed" update KB5015019 and test.

 

 

My VPN Server is not on the domain.

 

Using Computer Level Certs.

Posted (edited)

Btw is it only the DCs that are getting affected by the May update?

 

Would it be OK to apply the May updates on all other servers and leaving the DCs out?

Edited by Ertech
Posted (edited)
Btw is it only the DCs that are getting affected by the May update?

 

Would it be OK to apply the May updates on all other servers and leaving the DCs out?

 

There's an out of band to resolve the DC issues now anyway, so no harm in installing. Just needs the manual update applied after

 

https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015019-os-build-14393-5127-out-of-band-8548dfda-38ba-4fb6-a7a3-42b86ac2cc81

https://support.microsoft.com/en-gb/topic/may-19-2022-kb5015018-os-build-17763-2931-out-of-band-e4c28a4d-7dbe-4ef5-a539-f0b21cba2ebb

 

etc depending on which OS :p

 

(Edit - As a side note, as noticed someone above said about NPS still, it seems to depend on the order you install the updates to whether it resolves it. Regarding updating the CA first for PKI, resetting OID etc)

 

Steve

Edited by Steve21
Posted

 

 

Do just apply the out of band updates manually on the DCs after installing the May updates? - no need to apply out of band updates on any other server?

Posted
Do just apply the out of band updates manually on the DCs after installing the May updates? - no need to apply out of band updates on any other server?

 

Yes - but they're only available on the Windows Catalog and not Windows Update. All a manual process and only applies to DCs.

 

I'm half tempted to skip the May update on DCs and install the June update when it becomes available.

Posted
So out of curiosity, has anyone installed the May 2022 CU and the May OOB patch on either 2016 or 2019 DCs? I'm still on the April 2022 CU for all servers.

 

Installed the May 2022 CU on 2016 3 DCs and 1 CA server, so far no problems.

 

We use NPS and computer certificate for wireless connections.

 

Cant see any errors at all.

 

Cheers.

  • 1 month later...
Posted
I've skipped May and went to the June updates instead, installed over the weekend. Our AoVPN/NPS/RADIUS/CA all seem to be working, but not extensively tested all services. We don't use certs with our internal wifi which I know was one issue identified.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...