Microsoft CVE-2022-38023 and NTLMv2

Randy Rue <[email protected]> Fri, 7 Jul 2023 07:51:07 -0700
Newsgroups gmane.comp.hardware.netapp
Message-ID <CABWQgd35ojgPszS6mJ+rW-cdEmHesYbkCn8Hz7+TU6J-EoZhvQ@mail.gmail.com>
--===============0530260402437238775==
Content-Type: multipart/alternative; boundary="000000000000e8e2c905ffe6c34f"

--000000000000e8e2c905ffe6c34f
Content-Type: text/plain; charset="UTF-8"

Hello All,

We've upgraded our AFF-A220 to 9.13.1 as per
https://kb.netapp.com/Support_Bulletins/Customer_Bulletins/SU530

and should be all good to go for next Tuesday's closing of the door on
NTLMv2 authentication.

However,

scrb::> vserver cifs session show -vserver sdata -fields
auth-mechanism,address,windows-user
node     vserver    session-id           connection-id address
auth-mechanism windows-user
-------- ---------- -------------------- ------------- ---------------
-------------- ------------
scrb-a sdata      12223613813613660030 4271015427    10.6.154.156    NTLMv2
        FHC\rgrasdue

still shows all of our CIFS connections using NTLMv2 to authenticate (one
line is shown of hundreds of connections)

Are we ready for next week's update? Will the auth-mechanism change after
we patch our DCs? Or will all our CIFS connections break?

Let u s know,

Randy Rue

--000000000000e8e2c905ffe6c34f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hello All,<div><br></div><div>We&#39;ve upgraded our AFF-A=
220 to 9.13.1 as per=C2=A0<a href=3D"https://kb.netapp.com/Support_Bulletin=
s/Customer_Bulletins/SU530">https://kb.netapp.com/Support_Bulletins/Custome=
r_Bulletins/SU530</a></div><div><br></div><div>and should be all good to go=
 for next Tuesday&#39;s closing of the door on NTLMv2 authentication.</div>=
<div><br></div><div>However,</div><div><br></div><div>scrb::&gt; vserver ci=
fs session show -vserver sdata -fields auth-mechanism,address,windows-user<=
br>node =C2=A0 =C2=A0 vserver =C2=A0 =C2=A0session-id =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 connection-id address =C2=A0 =C2=A0 =C2=A0 =C2=A0 auth-mechan=
ism windows-user<br>-------- ---------- -------------------- ------------- =
--------------- -------------- ------------<br>scrb-a sdata =C2=A0 =C2=A0 =
=C2=A012223613813613660030 4271015427 =C2=A0 =C2=A010.6.154.156 =C2=A0 =C2=
=A0NTLMv2 =C2=A0 =C2=A0 =C2=A0 =C2=A0 FHC\rgrasdue<br></div><div><br></div>=
<div>still shows all of our CIFS connections using NTLMv2 to authenticate (=
one line is shown of hundreds of connections)</div><div><br></div><div>Are =
we ready for next week&#39;s update? Will the auth-mechanism change after w=
e patch our DCs? Or will all our CIFS connections break?</div><div><br></di=
v><div>Let u s know,</div><div><br></div><div>Randy Rue</div></div>

--000000000000e8e2c905ffe6c34f--

--===============0530260402437238775==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Toasters mailing list
[email protected]
https://www.teaparty.net/mailman/listinfo/toasters
--===============0530260402437238775==--