Jump to content

Recommended Posts

Posted

After running a recent security audit on AD, it highlighted that the Smoothwall object in AD still supports all insecure encryption types. This is shown in the msDS-SupportedEncryptionTypes attribute. I'm guessing that this is a legacy thing needed to support older devices?

 

By default the setting was on DES_CBC_CRC, DES_CBC_MD5, RC4-HMAC, AES128-CTS-HMAC-SHA1-96, AES256-CTS-HMAC-SHA1-96 and I've changed it to a default value that supports RC4_HMAC_MD5

 

On Microsoft's website it says the following regards DES encryption - DES encryption uses a 56-bit key to encrypt the content and is now considered to be highly insecure. Hence, accounts that can use DES to authenticate to services are at significantly greater risk of having that account’s logon sequence decrypted and the account compromised.

 

What are people's thoughts?

 

Thanks in advance

Posted

if your DC is above 2008 R2 DES will be disabled by default anyway, even if the msDS-SupportedEncryptionTypes attribute on the computer object supports it.

 

You can change this attribute on smoothwalls computer object to be 28 it should clear this warning and continue to work. (you can confirm this by running a diag on the directory in smoothwall)

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...