Re: Microsoft CVE-2022-38023 and NTLMv2
"John Stoffel" <[email protected]> Tue, 11 Jul 2023 17:23:01 -0400
| Newsgroups | gmane.comp.hardware.netapp |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Randy" =3D=3D Randy Rue <[email protected]> writes: > Hello All, > We've upgraded our AFF-A220 to 9.13.1 as per=A0 > https://kb.netapp.com/Support_Bulletins/Customer_Bulletins/SU530 > and should be all good to go for next Tuesday's closing of the door on NT= LMv2 authentication. > However, > scrb::> vserver cifs session show -vserver sdata -fields auth-mechanism,a= ddress,windows-user > node =A0 =A0 vserver =A0 =A0session-id =A0 =A0 =A0 =A0 =A0 connection-id = address =A0 =A0 =A0 =A0 auth-mechanism windows-user > -------- ---------- -------------------- ------------- --------------- --= ------------ ------------ > scrb-a sdata =A0 =A0 =A012223613813613660030 4271015427 =A0 =A010.6.154.1= 56 =A0 =A0NTLMv2 =A0 =A0 =A0 =A0 FHC\rgrasdue > still shows all of our CIFS connections using NTLMv2 to authenticate (one= line is shown of > hundreds of connections) > Are we ready for next week's update? Will the auth-mechanism change > after we patch our DCs? Or will all our CIFS connections break? I'm in the same boat, we have a 9.5P5 cluster which just shows NTLMv1 and NTLMv2 logins. Can't seem to get it to do kerberos. I suspect it's something on the DC side of things, but our admins there haven't found anything. My other system, running 9.3P17 (so definitely affected) is only showing kerberos logins, so we should be ok there no matter what. = John