Re: MS patches break CIFS: SU530 from Netapp

Eric Leonard <[email protected]> Sat, 8 Jul 2023 18:44:43 +0200
Newsgroups gmane.comp.hardware.netapp
Message-ID <CAK3vE_7vvDukvgJ-50=5XXwMB3Fpam2bQnrD1RLMRMRWbEbm=A@mail.gmail.com>
--===============2760374532013058033==
Content-Type: multipart/alternative; boundary="0000000000009eaf6d05fffc7d5c"

--0000000000009eaf6d05fffc7d5c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello John,

I think there is a special GPO that could be enabled see
https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netl=
ogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309=
-1d6a-304e-5ba73cd1a11e#bkmk_thegrouppolicy
in a separate OU where you could move your older Netapp clusters to
"bypass" the requirements

Hope it helps

Rgds

Eric Leonard



On Sat, Jul 8, 2023 at 11:02=E2=80=AFAM John Stoffel <[email protected]> wro=
te:

>
>
> Guys,
> Is anyone else running into this problem with the latest MS patches
> breaking CIFS, especially on older OnTap versions and systems?
>
> I can download various older releases, and I could even upgrade an old
> FAS8060 to a release which supposedly is fixed for this ... but the
> systems are out of support, but of course in production.
>
> Anyone talk with Netapp about a one time support fee to bring some
> legacy systems up to snuff?  Of course this seems to also just affect
> those people using older Domain Controllers with NTLMv1 and NTLMv2
> still enabled and in use.
>
> For those of you who haven't seen this, I've attached it here.  Looks
> like a total cluster f*ck too... since there's so little time to
> address this issue.
>
> _______________________________________________
> Toasters mailing list
> [email protected]
> https://www.teaparty.net/mailman/listinfo/toasters

--0000000000009eaf6d05fffc7d5c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hello John,</div><div><br></div><div>I think there is=
 a special GPO that could be enabled see <a href=3D"https://support.microso=
ft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-con=
nections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e=
#bkmk_thegrouppolicy">https://support.microsoft.com/en-us/topic/how-to-mana=
ge-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2=
020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#bkmk_thegrouppolicy</a> in a =
separate OU where you could move your older Netapp clusters to &quot;bypass=
&quot; the requirements</div><div><br></div><div>Hope it helps</div><div><b=
r></div><div>Rgds</div><div><br></div><div>Eric Leonard</div><div><br></div=
><div><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Sat, Jul 8, 2023 at 11:02=E2=80=AFAM John Stoffel &lt;<a=
 href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br></div>=
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex"><br>
<br>
Guys,<br>
Is anyone else running into this problem with the latest MS patches<br>
breaking CIFS, especially on older OnTap versions and systems?=C2=A0 <br>
<br>
I can download various older releases, and I could even upgrade an old<br>
FAS8060 to a release which supposedly is fixed for this ... but the<br>
systems are out of support, but of course in production.=C2=A0 <br>
<br>
Anyone talk with Netapp about a one time support fee to bring some<br>
legacy systems up to snuff?=C2=A0 Of course this seems to also just affect<=
br>
those people using older Domain Controllers with NTLMv1 and NTLMv2<br>
still enabled and in use.=C2=A0 =C2=A0 <br>
<br>
For those of you who haven&#39;t seen this, I&#39;ve attached it here.=C2=
=A0 Looks<br>
like a total cluster f*ck too... since there&#39;s so little time to<br>
address this issue.<br>
<br>
_______________________________________________<br>
Toasters mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">Toasters@teapart=
y.net</a><br>
<a href=3D"https://www.teaparty.net/mailman/listinfo/toasters" rel=3D"noref=
errer" target=3D"_blank">https://www.teaparty.net/mailman/listinfo/toasters=
</a></blockquote></div>

--0000000000009eaf6d05fffc7d5c--

--===============2760374532013058033==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Toasters mailing list
[email protected]
https://www.teaparty.net/mailman/listinfo/toasters
--===============2760374532013058033==--