(unknown)

Fred Grieco via Toasters <[email protected]> Fri, 7 Jul 2023 17:19:48 +0100
Newsgroups gmane.comp.hardware.netapp
Message-ID <[email protected]>
--===============8860049192084217633==
Content-Type: message/rfc822
Content-Disposition: inline

Received: from sonic316-54.consmr.mail.gq1.yahoo.com
 (sonic316-54.consmr.mail.gq1.yahoo.com [98.137.69.30])
 by dormouse.teaparty.net (8.14.7/8.14.7) with ESMTP id 367GJine031751
 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO)
 for <[email protected]>; Fri, 7 Jul 2023 17:19:46 +0100
Authentication-Results: dormouse.teaparty.net;
 spf=pass [email protected]
 smtp.helo=sonic316-54.consmr.mail.gq1.yahoo.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048;
 t=1688746783; bh=I/FqMjfKmHyWZnYDQknyyTRlmPITQelS/uI6K162ymc=;
 h=Date:From:To:In-Reply-To:References:Subject:From:Subject:Reply-To;
 b=fm/akBxgCGsUJn4kxt5rOTCo0n9wQC35FTKrqaR1SwyWRgOqDKjklogcD0FdkOi5LOrJ/ZMPJhbDPDedWiAuu++YlTlzP68Zvvm6rHK4kzEVF8B+Q4Vo8Crdm2MAMU9H05VWD1mQsTAl6iCuAh40OtsC8Ce/2RNNWGRwn5oPBjjGRJ4G7cNgeyfWRcGpVISMcSA5iYV6H3h1M2do4IiE9H68XW1ycWQlOf+Bh2wikkLH1yJSEbKctp0ka+WX+EBDWOifeK1ywKlkgC1F2Bj4JIKEKEFwBbtYPPIE2IxTPDv2s3dhQdqM47W8IN7jniDkrj49MBlM2TLfPMtS3R3/lQ==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048;
 t=1688746783; bh=JbOA1LX7ul+BM3yEbr9DAfU83fakyEQtPxVkcAWBP2T=;
 h=X-Sonic-MF:Date:From:To:Subject:From:Subject;
 b=D7eQwqJsVIFXYT/DeGpXYUXR05Oe1HHhekD0ndSigX72At8T+CrfX2ctKMJafSoUiz9LAogChcoJkmDY+/42WZS2B7g1GPFcsnAMhMTNK+4i7C2tHfTk/N1oH5c0lTocugESroNCXfwTULt7bHO5afIrTUivS5+XQjIAnn+nNNRoP1UHpmacY74/09Bxt9i3Apqnd+IcEcVXCZw+t66mR5X7EbXmLaJ9Ur/gHA24TXDfqdctojXC2Ppa2WBO+rk7uIrKBsYiJeXc1jDWHSQOaSs9Hb5bz97Uktz5+Qpz2YFk8/4rWZDU1cWKQfc91yTZ/Hme7kOaMnMDxfKVFfz8Qw==
X-YMail-OSG: K.JtSuIVM1mC_5shHY1.c9VBz9cdF2u_cg5u5r8rAMaClbSkScMcje7AoruXVYf
 GJsSyvPNqHZ.QCxiNm7Z.0hp9mBajhxtLbKM866o5kJA4T.XkVxodwvHOfM7NUC_xVTrEP.NV77Y
 dAMu77KO_2_gIBzJH6diHByWmYRor08I5ADykMnoTCBepKHmMIVwOe.05OqzbgodKVzM9hd8NVv9
 8pwJjd4nF8xxZ4Bgjbgmcyltalj67CEMZK4Xve9LRgCCve0THbQgc8L_bk2f9CbQftTS4Yn0s71m
 xaJoMWgtAoj4oUnK7lWV6uFYHkzop_t4B30cS663sUsuCZ7SQK5yIBUENAOIXEE_zd_XfTLTKK8M
 BMF_ohEh5_Plzz5_XoCb9nMApxhBDmlAMYhXH.C5.XNwXzVHjUkY3L9Z_5rphuqrQNBZIxuyYcjO
 uQloBvN9yu5cfvFq9fGGg9q8rJyNQZa3CjKd.FvQGwaTVMHfMwHrUXYAzgS8cKaKJVqjlows2qwR
 i7WwpkjTxV4dCqCqpyUhU5yiDTA04RSqeqZ2vaA_8kKYOM1gy4Ggm5r4p9o5reVLaxckpgHjBA4a
 ciwaZIiFYcePouBlV9yje7GVCxwoS8HUphMk1wg1OaaHsQK6BItSfsl1DbjQ9fMnpSM6vAIN9r7l
 Iolb1d9gpStIcCBAfzlGNcpS5QRlvioRHPK0kf_xMljOniYrvtQgckcZydIT3qmQh.wqtmvVH_Ru
 oMPbYgFV.kMpc3JhIwEYshpCfMKPP7wQEHCexWOtvbLqkiriMm03OPUM2E5SN6Eia.RRpVsuGqUS
 wbnqmwR14U_5V1K60tkL39x9WzUPF1j_o8dgkWpc5aNbuwFaF01qdEckkwXeFCVhOmL5xg9HdQVU
 UDnbi_5y_j8ELUksp8hhxHDQ2sPZ2hABx4.rd1dj0X.gETssh6kcn6VV8_JdUBG2vDsaY5Xpc4pr
 W9VOkNV4f0eSLaFWLLiVxoeISG7gElCPzOFz6._ecB4W5X1JIeM6iMQKUFh7PnWS3pIB1WL10vFK
 Rw4tGhlspSulbjY9Fs_eLG7W_FescaPIImqJltiMjp_5iAX37uCa3Zh8URT7TBxUhbT0FoWQWGg6
 WRWLRxgk6Rt79Ue0FXfJYSVHFiqKKrDZjsXwYCk1Gx9EdeJgs2d1HkOJeOSP34QeDWSsZbivJx37
 a6Obt76DzdzsFtKSX21asNwezt90FtOmXujnduH1zBujkPztwNxBODzRN9bJLKQTgvx6dJwgGPmQ
 o04i643frD1OPxX2wkNT.Nb4KhG7Kdd_.F5NOz8l5xIXsWrcWENOQaZ8yJAjUtjT4RBEZHY0mkzA
 7eLwgGi83FQVjvtbG.JoV6hC4painPSKUHhyUtJ893kJTlLTotNtdOWJNTZW3qx3BhUwvNi891z9
 ZTkuboHM3uY1XRNo_UARg_Nuqgash5lx7Sh5OU9Hsruc5gpMJDcE3mY7ZY4CONjrIR7pnxPLP_9a
 cZFMWzshVTuX2ipGmxyp9bScNuqayhLOpAhsUxCHfDp0GPtL3v68P41In3aSroAE7vV2nos_qG3P
 Z2xlkojDDB0Nx3Li6xLckNQJ_9fieWRvSCZb9KBwsHxyPK3N_aa.wfLIWATp8gE7t6THH6aQtgty
 DfvQXeto4gb2ChXi3eFTAI4drU.HtDlrLHRkpsYta7QVrPqI9dUU_RYddmuLvJ.1B9BL41xIDf4u
 6smqd0h7JsD5zqLaAH85sCHGSTFVO.bKdb4NEDymL.aXmiGS1p7F.OO4Gaz0JlL8Zj.nhbCjb6L9
 weZ7BfFkG86yzcGIMw.rj1Uw.sShc0ORfcPuiQwigcqmkYwizlv2R0EV9z7HBvtEWigXPPfHefd9
 WTV3sYqnPB_jS_1PTuUjaT5xyTEkz2Kar_iT1ayggvsCqartQk0iq2DCH7Ko0QpqKXgl_7rONITZ
 fzY8pn4qz.G3O3hOy3jtC0IsDRAg53ptziKrdyn9ss_fdzeWQRpulleeOQ01OMu9zqBjDhcWjqK3
 I7WEGH1vaVkx0._YZkgV2AgKULhbafHDTGG0QNbQjLi..jqiCFB.OBeM55Laoae_51rkzgKplgYg
 J0RKFkp32BAatvLMpBvtFuje7amcbDGVaWtE1lAXBymx1eM3laNehtrbyhD9GZYz_QVbJnsv.ELu
 YJd8EQGHFqtBPapYXrBV5gRiGfuPbXSyBs2YSAVjvlgmjKyufAa6cwMailj4AvKzSkgv0HagkigM
 9dS._ZZcu9QZw0_Cnb1UHuvOc
X-Sonic-MF: <[email protected]>
X-Sonic-ID: 459f77f4-b21d-4a02-8728-afccfdf38ed5
Received: from sonic.gate.mail.ne1.yahoo.com by
 sonic316.consmr.mail.gq1.yahoo.com with HTTP; Fri, 7 Jul 2023 16:19:43 +0000
Date: Fri, 7 Jul 2023 16:19:39 +0000 (UTC)
From: Fred Grieco <[email protected]>
To: Toasters <[email protected]>, Randy Rue <[email protected]>
Message-ID: <[email protected]>
In-Reply-To: <CABWQgd35ojgPszS6mJ+rW-cdEmHesYbkCn8Hz7+TU6J-EoZhvQ@mail.gmail.com>
References: <CABWQgd35ojgPszS6mJ+rW-cdEmHesYbkCn8Hz7+TU6J-EoZhvQ@mail.gmail.com>
Subject: Re: Microsoft CVE-2022-38023 and NTLMv2
MIME-Version: 1.0
Content-Type: multipart/alternative; 
 boundary="----=_Part_782283_1436767366.1688746779679"
X-Mailer: WebService/1.1.21638 YMailNorrin
X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.2
 (dormouse.teaparty.net [178.18.123.145]);
 Fri, 07 Jul 2023 17:19:46 +0100 (BST)

------=_Part_782283_1436767366.1688746779679
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

 Randy,
As far as I know, the MS patch will just require sealing on Netlogon connec=
tions.=C2=A0 They will still be allowed.=C2=A0 I had opened a case with Net=
app support, and this is not a tunable parameter, it's just build into the =
patch.=C2=A0 So you should be good.
There is another tunable parameter, "cifs security modify -vserver vserver =
-aes-enabled-for-netlogon-channel"=C2=A0 You may want to set this to true.=
=C2=A0 Our windows engineers warned us that this will be a "next step" in M=
S's lockdown of auth security.
FWIW, almost all of our clients are <=3DSMBv3 with kerberos auth, but we do=
 notice the SVMs themselves make NTLMv2 auth to the domain controllers from=
 time to time (on 9.10.1P12)

Fred
    On Friday, July 7, 2023 at 10:58:43 AM EDT, Randy Rue <[email protected]=
om> wrote: =20
=20
 Hello All,
We've upgraded our AFF-A220 to 9.13.1 as per=C2=A0https://kb.netapp.com/Sup=
port_Bulletins/Customer_Bulletins/SU530
and should be all good to go for next Tuesday's closing of the door on NTLM=
v2 authentication.
However,
scrb::> vserver cifs session show -vserver sdata -fields auth-mechanism,add=
ress,windows-user
node =C2=A0 =C2=A0 vserver =C2=A0 =C2=A0session-id =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 connection-id address =C2=A0 =C2=A0 =C2=A0 =C2=A0 auth-mechanism=
 windows-user
-------- ---------- -------------------- ------------- --------------- ----=
---------- ------------
scrb-a sdata =C2=A0 =C2=A0 =C2=A012223613813613660030 4271015427 =C2=A0 =C2=
=A010.6.154.156 =C2=A0 =C2=A0NTLMv2 =C2=A0 =C2=A0 =C2=A0 =C2=A0 FHC\rgrasdu=
e

still shows all of our CIFS connections using NTLMv2 to authenticate (one l=
ine is shown of hundreds of connections)
Are we ready for next week's update? Will the auth-mechanism change after w=
e patch our DCs? Or will all our CIFS connections break?
Let u s know,
Randy Rue_______________________________________________
Toasters mailing list
[email protected]
https://www.teaparty.net/mailman/listinfo/toasters =20
------=_Part_782283_1436767366.1688746779679
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><div class=3D"ydp56036e55yahoo-style-wrap" style=
=3D"font-family:Helvetica Neue, Helvetica, Arial, sans-serif;font-size:16px=
;"><div></div>
        <div dir=3D"ltr" data-setdir=3D"false">Randy,</div><div dir=3D"ltr"=
 data-setdir=3D"false"><br></div><div dir=3D"ltr" data-setdir=3D"false">As =
far as I know, the MS patch will just require sealing on Netlogon connectio=
ns.&nbsp; They will still be allowed.&nbsp; I had opened a case with Netapp=
 support, and this is not a tunable parameter, it's just build into the pat=
ch.&nbsp; So you should be good.</div><div dir=3D"ltr" data-setdir=3D"false=
"><br><div>There is another tunable parameter, "cifs security modify -vserv=
er vserver -aes-enabled-for-netlogon-channel"&nbsp; You may want to set thi=
s to true.&nbsp; Our windows engineers warned us that this will be a "next =
step" in MS's lockdown of auth security.</div><div><br></div><div dir=3D"lt=
r" data-setdir=3D"false">FWIW, almost all of our clients are &lt;=3DSMBv3 w=
ith kerberos auth, but we do notice the SVMs themselves make NTLMv2 auth to=
 the domain controllers from time to time (on 9.10.1P12)<br><br><div>Fred</=
div></div></div><div><br></div>
       =20
        </div><div id=3D"ydp8729f7c8yahoo_quoted_9656267394" class=3D"ydp87=
29f7c8yahoo_quoted">
            <div style=3D"font-family:'Helvetica Neue', Helvetica, Arial, s=
ans-serif;font-size:13px;color:#26282a;">
               =20
                <div>
                    On Friday, July 7, 2023 at 10:58:43 AM EDT, Randy Rue &=
lt;[email protected]&gt; wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div><div id=3D"ydp8729f7c8yiv0792600585"><div dir=3D"ltr">=
Hello All,<div><br></div><div>We've upgraded our AFF-A220 to 9.13.1 as per&=
nbsp;<a href=3D"https://kb.netapp.com/Support_Bulletins/Customer_Bulletins/=
SU530" rel=3D"nofollow" target=3D"_blank">https://kb.netapp.com/Support_Bul=
letins/Customer_Bulletins/SU530</a></div><div><br></div><div>and should be =
all good to go for next Tuesday's closing of the door on NTLMv2 authenticat=
ion.</div><div><br></div><div>However,</div><div><br></div><div>scrb::&gt; =
vserver cifs session show -vserver sdata -fields auth-mechanism,address,win=
dows-user<br>node &nbsp; &nbsp; vserver &nbsp; &nbsp;session-id &nbsp; &nbs=
p; &nbsp; &nbsp; &nbsp; connection-id address &nbsp; &nbsp; &nbsp; &nbsp; a=
uth-mechanism windows-user<br>-------- ---------- -------------------- ----=
--------- --------------- -------------- ------------<br>scrb-a sdata &nbsp=
; &nbsp; &nbsp;12223613813613660030 4271015427 &nbsp; &nbsp;10.6.154.156 &n=
bsp; &nbsp;NTLMv2 &nbsp; &nbsp; &nbsp; &nbsp; FHC\rgrasdue<br></div><div><b=
r></div><div>still shows all of our CIFS connections using NTLMv2 to authen=
ticate (one line is shown of hundreds of connections)</div><div><br></div><=
div>Are we ready for next week's update? Will the auth-mechanism change aft=
er we patch our DCs? Or will all our CIFS connections break?</div><div><br>=
</div><div>Let u s know,</div><div><br></div><div>Randy Rue</div></div>
</div>_______________________________________________<br>Toasters mailing l=
ist<br><a href=3D"mailto:[email protected]" rel=3D"nofollow" target=3D"=
_blank">[email protected]</a><br><a href=3D"https://www.teaparty.net/ma=
ilman/listinfo/toasters" rel=3D"nofollow" target=3D"_blank">https://www.tea=
party.net/mailman/listinfo/toasters</a></div>
            </div>
        </div></body></html>
------=_Part_782283_1436767366.1688746779679--

--===============8860049192084217633==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Toasters mailing list
[email protected]
https://www.teaparty.net/mailman/listinfo/toasters
--===============8860049192084217633==--