#ONTAP 7-mode 8.2 CIFS after Netlogon CVE-2022-38023 July hardening
1 messages · Page 1 of 1 (latest)
Thanks! So adding ad computer filer accounts to this gpo "Domain Controller: Allow vulnerable Netlogon secure channel connections” will let them survive? Is that all? Their OS is plain 8.2.
That's how I read it.
Much appreciated
My read is that in enforcement stage, that workaround stops working, so they’re just buying themselves a few weeks
We should clarify that page..
mmm... you could be correct on that based on a few other things I am reading.. you have time to submit?
if not i can.
I've submitted feedback on that article
7-mode is toast unless you're doing block or non-AD-kerberos NFS
it's been 9 years. Time to give it up.
much thanks good sir.
Guys thanks for update and clarifying this! One more thing that will help us convince them to buy new hardware and move to ONTAP 9
My impression (oh hi @stoic folio ) is that running 8.2.5P5 with options cifs.netlogon.secure_channel.enable on will still work with AD kerberos. only NTLM will stop working (as I found today when not using the correct domain name). but yes, don't tell your customer that
👋
I’ve done some more reading and we think you’re right, but it’s a low confidence understanding
The comment was that 7-mode auth is totally insecure anyway, so it’s allowed by a different set of config
meanwhile, time to delete some volumes that have snapvault lag times of over 2000 days
one is nearly at 3000 days
the other fun one is https://kb.netapp.com/Legacy/ONTAP/7Mode/CIFS_share_inaccessible_after_disabling_RC4_on_7mode_and_DC which is a hard block when RC4 is disabled in AD
yes the RC4 has been a showstopper for 7mode for a while. But it's easy to work around. The NTLM change cannot be worked around
gah, rc4 was briefly disabled and it worked for a bit but now I'm getting kerberos etype errors