Jump to content

Recommended Posts

Posted

Just noticed an issue when I try to RDP from a fully patched Win11 Pro desktop to a fully patched Server 2019 1809 server, and we get the old CredSSP error - now I haven't seen that since the early days of Win 10/Server 2016

 

With both systems fully patched I'm not sure how to resolve this, apart from switching the 'encryption oracle remediation' setting to vulnerable which seems like a dangerous and massively backwards step - has anyone seen this error recently?

  • 3 weeks later...
Posted

Had the same issue

 

Solution for me:

If you're on a domain, use the full server name to connect to, like: servername.domain.local

Just 'servername' won't work even if it resolves fine

 

I assume this has to do with Kerberos authentication in the domain and NTLM being disabled on the domain

Needs FQDN to do auth

 

Sad to see admins still enabling NTLM or bypassing other security measures to get it working

Even worse is people not disabling the setting in GUI (remote logon settings > uncheck 'Network Level Auth'), because it is not secure, but then running the powershell script to disable exactly that.

 

GL HF

  • Thanks 1
Posted
Unfortunately I still get this error even with FQDN - the only way I've found around it was to RDP to another server, and then hop to the other one!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...