(unknown)
Fred Grieco via Toasters <[email protected]> Fri, 7 Jul 2023 17:19:48 +0100
| Newsgroups | gmane.comp.hardware.netapp |
|---|---|
| Message-ID | <[email protected]> |
--===============8860049192084217633== Content-Type: message/rfc822 Content-Disposition: inline Received: from sonic316-54.consmr.mail.gq1.yahoo.com (sonic316-54.consmr.mail.gq1.yahoo.com [98.137.69.30]) by dormouse.teaparty.net (8.14.7/8.14.7) with ESMTP id 367GJine031751 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO) for <[email protected]>; Fri, 7 Jul 2023 17:19:46 +0100 Authentication-Results: dormouse.teaparty.net; spf=pass [email protected] smtp.helo=sonic316-54.consmr.mail.gq1.yahoo.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1688746783; bh=I/FqMjfKmHyWZnYDQknyyTRlmPITQelS/uI6K162ymc=; h=Date:From:To:In-Reply-To:References:Subject:From:Subject:Reply-To; b=fm/akBxgCGsUJn4kxt5rOTCo0n9wQC35FTKrqaR1SwyWRgOqDKjklogcD0FdkOi5LOrJ/ZMPJhbDPDedWiAuu++YlTlzP68Zvvm6rHK4kzEVF8B+Q4Vo8Crdm2MAMU9H05VWD1mQsTAl6iCuAh40OtsC8Ce/2RNNWGRwn5oPBjjGRJ4G7cNgeyfWRcGpVISMcSA5iYV6H3h1M2do4IiE9H68XW1ycWQlOf+Bh2wikkLH1yJSEbKctp0ka+WX+EBDWOifeK1ywKlkgC1F2Bj4JIKEKEFwBbtYPPIE2IxTPDv2s3dhQdqM47W8IN7jniDkrj49MBlM2TLfPMtS3R3/lQ== X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1688746783; bh=JbOA1LX7ul+BM3yEbr9DAfU83fakyEQtPxVkcAWBP2T=; h=X-Sonic-MF:Date:From:To:Subject:From:Subject; b=D7eQwqJsVIFXYT/DeGpXYUXR05Oe1HHhekD0ndSigX72At8T+CrfX2ctKMJafSoUiz9LAogChcoJkmDY+/42WZS2B7g1GPFcsnAMhMTNK+4i7C2tHfTk/N1oH5c0lTocugESroNCXfwTULt7bHO5afIrTUivS5+XQjIAnn+nNNRoP1UHpmacY74/09Bxt9i3Apqnd+IcEcVXCZw+t66mR5X7EbXmLaJ9Ur/gHA24TXDfqdctojXC2Ppa2WBO+rk7uIrKBsYiJeXc1jDWHSQOaSs9Hb5bz97Uktz5+Qpz2YFk8/4rWZDU1cWKQfc91yTZ/Hme7kOaMnMDxfKVFfz8Qw== X-YMail-OSG: K.JtSuIVM1mC_5shHY1.c9VBz9cdF2u_cg5u5r8rAMaClbSkScMcje7AoruXVYf GJsSyvPNqHZ.QCxiNm7Z.0hp9mBajhxtLbKM866o5kJA4T.XkVxodwvHOfM7NUC_xVTrEP.NV77Y dAMu77KO_2_gIBzJH6diHByWmYRor08I5ADykMnoTCBepKHmMIVwOe.05OqzbgodKVzM9hd8NVv9 8pwJjd4nF8xxZ4Bgjbgmcyltalj67CEMZK4Xve9LRgCCve0THbQgc8L_bk2f9CbQftTS4Yn0s71m xaJoMWgtAoj4oUnK7lWV6uFYHkzop_t4B30cS663sUsuCZ7SQK5yIBUENAOIXEE_zd_XfTLTKK8M BMF_ohEh5_Plzz5_XoCb9nMApxhBDmlAMYhXH.C5.XNwXzVHjUkY3L9Z_5rphuqrQNBZIxuyYcjO uQloBvN9yu5cfvFq9fGGg9q8rJyNQZa3CjKd.FvQGwaTVMHfMwHrUXYAzgS8cKaKJVqjlows2qwR i7WwpkjTxV4dCqCqpyUhU5yiDTA04RSqeqZ2vaA_8kKYOM1gy4Ggm5r4p9o5reVLaxckpgHjBA4a ciwaZIiFYcePouBlV9yje7GVCxwoS8HUphMk1wg1OaaHsQK6BItSfsl1DbjQ9fMnpSM6vAIN9r7l Iolb1d9gpStIcCBAfzlGNcpS5QRlvioRHPK0kf_xMljOniYrvtQgckcZydIT3qmQh.wqtmvVH_Ru oMPbYgFV.kMpc3JhIwEYshpCfMKPP7wQEHCexWOtvbLqkiriMm03OPUM2E5SN6Eia.RRpVsuGqUS wbnqmwR14U_5V1K60tkL39x9WzUPF1j_o8dgkWpc5aNbuwFaF01qdEckkwXeFCVhOmL5xg9HdQVU UDnbi_5y_j8ELUksp8hhxHDQ2sPZ2hABx4.rd1dj0X.gETssh6kcn6VV8_JdUBG2vDsaY5Xpc4pr W9VOkNV4f0eSLaFWLLiVxoeISG7gElCPzOFz6._ecB4W5X1JIeM6iMQKUFh7PnWS3pIB1WL10vFK Rw4tGhlspSulbjY9Fs_eLG7W_FescaPIImqJltiMjp_5iAX37uCa3Zh8URT7TBxUhbT0FoWQWGg6 WRWLRxgk6Rt79Ue0FXfJYSVHFiqKKrDZjsXwYCk1Gx9EdeJgs2d1HkOJeOSP34QeDWSsZbivJx37 a6Obt76DzdzsFtKSX21asNwezt90FtOmXujnduH1zBujkPztwNxBODzRN9bJLKQTgvx6dJwgGPmQ o04i643frD1OPxX2wkNT.Nb4KhG7Kdd_.F5NOz8l5xIXsWrcWENOQaZ8yJAjUtjT4RBEZHY0mkzA 7eLwgGi83FQVjvtbG.JoV6hC4painPSKUHhyUtJ893kJTlLTotNtdOWJNTZW3qx3BhUwvNi891z9 ZTkuboHM3uY1XRNo_UARg_Nuqgash5lx7Sh5OU9Hsruc5gpMJDcE3mY7ZY4CONjrIR7pnxPLP_9a cZFMWzshVTuX2ipGmxyp9bScNuqayhLOpAhsUxCHfDp0GPtL3v68P41In3aSroAE7vV2nos_qG3P Z2xlkojDDB0Nx3Li6xLckNQJ_9fieWRvSCZb9KBwsHxyPK3N_aa.wfLIWATp8gE7t6THH6aQtgty DfvQXeto4gb2ChXi3eFTAI4drU.HtDlrLHRkpsYta7QVrPqI9dUU_RYddmuLvJ.1B9BL41xIDf4u 6smqd0h7JsD5zqLaAH85sCHGSTFVO.bKdb4NEDymL.aXmiGS1p7F.OO4Gaz0JlL8Zj.nhbCjb6L9 weZ7BfFkG86yzcGIMw.rj1Uw.sShc0ORfcPuiQwigcqmkYwizlv2R0EV9z7HBvtEWigXPPfHefd9 WTV3sYqnPB_jS_1PTuUjaT5xyTEkz2Kar_iT1ayggvsCqartQk0iq2DCH7Ko0QpqKXgl_7rONITZ fzY8pn4qz.G3O3hOy3jtC0IsDRAg53ptziKrdyn9ss_fdzeWQRpulleeOQ01OMu9zqBjDhcWjqK3 I7WEGH1vaVkx0._YZkgV2AgKULhbafHDTGG0QNbQjLi..jqiCFB.OBeM55Laoae_51rkzgKplgYg J0RKFkp32BAatvLMpBvtFuje7amcbDGVaWtE1lAXBymx1eM3laNehtrbyhD9GZYz_QVbJnsv.ELu YJd8EQGHFqtBPapYXrBV5gRiGfuPbXSyBs2YSAVjvlgmjKyufAa6cwMailj4AvKzSkgv0HagkigM 9dS._ZZcu9QZw0_Cnb1UHuvOc X-Sonic-MF: <[email protected]> X-Sonic-ID: 459f77f4-b21d-4a02-8728-afccfdf38ed5 Received: from sonic.gate.mail.ne1.yahoo.com by sonic316.consmr.mail.gq1.yahoo.com with HTTP; Fri, 7 Jul 2023 16:19:43 +0000 Date: Fri, 7 Jul 2023 16:19:39 +0000 (UTC) From: Fred Grieco <[email protected]> To: Toasters <[email protected]>, Randy Rue <[email protected]> Message-ID: <[email protected]> In-Reply-To: <CABWQgd35ojgPszS6mJ+rW-cdEmHesYbkCn8Hz7+TU6J-EoZhvQ@mail.gmail.com> References: <CABWQgd35ojgPszS6mJ+rW-cdEmHesYbkCn8Hz7+TU6J-EoZhvQ@mail.gmail.com> Subject: Re: Microsoft CVE-2022-38023 and NTLMv2 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_782283_1436767366.1688746779679" X-Mailer: WebService/1.1.21638 YMailNorrin X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.2 (dormouse.teaparty.net [178.18.123.145]); Fri, 07 Jul 2023 17:19:46 +0100 (BST) ------=_Part_782283_1436767366.1688746779679 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Randy, As far as I know, the MS patch will just require sealing on Netlogon connec= tions.=C2=A0 They will still be allowed.=C2=A0 I had opened a case with Net= app support, and this is not a tunable parameter, it's just build into the = patch.=C2=A0 So you should be good. There is another tunable parameter, "cifs security modify -vserver vserver = -aes-enabled-for-netlogon-channel"=C2=A0 You may want to set this to true.= =C2=A0 Our windows engineers warned us that this will be a "next step" in M= S's lockdown of auth security. FWIW, almost all of our clients are <=3DSMBv3 with kerberos auth, but we do= notice the SVMs themselves make NTLMv2 auth to the domain controllers from= time to time (on 9.10.1P12) Fred On Friday, July 7, 2023 at 10:58:43 AM EDT, Randy Rue <[email protected]= om> wrote: =20 =20 Hello All, We've upgraded our AFF-A220 to 9.13.1 as per=C2=A0https://kb.netapp.com/Sup= port_Bulletins/Customer_Bulletins/SU530 and should be all good to go for next Tuesday's closing of the door on NTLM= v2 authentication. However, scrb::> vserver cifs session show -vserver sdata -fields auth-mechanism,add= ress,windows-user node =C2=A0 =C2=A0 vserver =C2=A0 =C2=A0session-id =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 connection-id address =C2=A0 =C2=A0 =C2=A0 =C2=A0 auth-mechanism= windows-user -------- ---------- -------------------- ------------- --------------- ----= ---------- ------------ scrb-a sdata =C2=A0 =C2=A0 =C2=A012223613813613660030 4271015427 =C2=A0 =C2= =A010.6.154.156 =C2=A0 =C2=A0NTLMv2 =C2=A0 =C2=A0 =C2=A0 =C2=A0 FHC\rgrasdu= e still shows all of our CIFS connections using NTLMv2 to authenticate (one l= ine is shown of hundreds of connections) Are we ready for next week's update? Will the auth-mechanism change after w= e patch our DCs? Or will all our CIFS connections break? Let u s know, Randy Rue_______________________________________________ Toasters mailing list [email protected] https://www.teaparty.net/mailman/listinfo/toasters =20 ------=_Part_782283_1436767366.1688746779679 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <html><head></head><body><div class=3D"ydp56036e55yahoo-style-wrap" style= =3D"font-family:Helvetica Neue, Helvetica, Arial, sans-serif;font-size:16px= ;"><div></div> <div dir=3D"ltr" data-setdir=3D"false">Randy,</div><div dir=3D"ltr"= data-setdir=3D"false"><br></div><div dir=3D"ltr" data-setdir=3D"false">As = far as I know, the MS patch will just require sealing on Netlogon connectio= ns. They will still be allowed. I had opened a case with Netapp= support, and this is not a tunable parameter, it's just build into the pat= ch. So you should be good.</div><div dir=3D"ltr" data-setdir=3D"false= "><br><div>There is another tunable parameter, "cifs security modify -vserv= er vserver -aes-enabled-for-netlogon-channel" You may want to set thi= s to true. Our windows engineers warned us that this will be a "next = step" in MS's lockdown of auth security.</div><div><br></div><div dir=3D"lt= r" data-setdir=3D"false">FWIW, almost all of our clients are <=3DSMBv3 w= ith kerberos auth, but we do notice the SVMs themselves make NTLMv2 auth to= the domain controllers from time to time (on 9.10.1P12)<br><br><div>Fred</= div></div></div><div><br></div> =20 </div><div id=3D"ydp8729f7c8yahoo_quoted_9656267394" class=3D"ydp87= 29f7c8yahoo_quoted"> <div style=3D"font-family:'Helvetica Neue', Helvetica, Arial, s= ans-serif;font-size:13px;color:#26282a;"> =20 <div> On Friday, July 7, 2023 at 10:58:43 AM EDT, Randy Rue &= lt;[email protected]> wrote: </div> <div><br></div> <div><br></div> <div><div id=3D"ydp8729f7c8yiv0792600585"><div dir=3D"ltr">= Hello All,<div><br></div><div>We've upgraded our AFF-A220 to 9.13.1 as per&= nbsp;<a href=3D"https://kb.netapp.com/Support_Bulletins/Customer_Bulletins/= SU530" rel=3D"nofollow" target=3D"_blank">https://kb.netapp.com/Support_Bul= letins/Customer_Bulletins/SU530</a></div><div><br></div><div>and should be = all good to go for next Tuesday's closing of the door on NTLMv2 authenticat= ion.</div><div><br></div><div>However,</div><div><br></div><div>scrb::> = vserver cifs session show -vserver sdata -fields auth-mechanism,address,win= dows-user<br>node vserver session-id &nbs= p; connection-id address a= uth-mechanism windows-user<br>-------- ---------- -------------------- ----= --------- --------------- -------------- ------------<br>scrb-a sdata  = ; 12223613813613660030 4271015427 10.6.154.156 &n= bsp; NTLMv2 FHC\rgrasdue<br></div><div><b= r></div><div>still shows all of our CIFS connections using NTLMv2 to authen= ticate (one line is shown of hundreds of connections)</div><div><br></div><= div>Are we ready for next week's update? Will the auth-mechanism change aft= er we patch our DCs? Or will all our CIFS connections break?</div><div><br>= </div><div>Let u s know,</div><div><br></div><div>Randy Rue</div></div> </div>_______________________________________________<br>Toasters mailing l= ist<br><a href=3D"mailto:[email protected]" rel=3D"nofollow" target=3D"= _blank">[email protected]</a><br><a href=3D"https://www.teaparty.net/ma= ilman/listinfo/toasters" rel=3D"nofollow" target=3D"_blank">https://www.tea= party.net/mailman/listinfo/toasters</a></div> </div> </div></body></html> ------=_Part_782283_1436767366.1688746779679-- --===============8860049192084217633== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Toasters mailing list [email protected] https://www.teaparty.net/mailman/listinfo/toasters --===============8860049192084217633==--