So, among a few hundred other things, we got dinged on a security
audit for SMB packet security. Right now, I have a GPO that signs the
packets, if client and server agree:
Computer Policy - Disable SMBv1 and enforce SMB signing
Microsoft network client: Digitally sign communications (if server agrees)
Computer Policy - Disable SMBv1 and enforce SMB signing
Microsoft network server: Digitally sign communications (if client agrees)
Problem is, that policy is only applied to our Servers OU, and not all
client computers (i.e., workstations). If I change to "Digitally sign
communications (always)", which is what the security company wants
(and I agree), don't I have to have all 3 options, AND apply this GPO
to ALL computer objects in the domain? Else the client OSes won't be
able to talk to the server OSes, since the Server OSes will require
signing, but the Client OSes have no setting (at the moment).
Am I missing something?
I'm thinking I apply the current GPO to all computer objects in the
domain today. Then next week, change the option to "Always" for client
and server.
And it should Just Be Transparent. :-)
Yes?
--
Mike. Leone, <mailto:
tur...@mike-leone.com>
PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <
http://www.flickr.com/photos/mikeleonephotos>