Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LAN Manager authentication level incorrect #25

Closed
JCapriotti opened this issue Dec 6, 2018 · 1 comment
Closed

LAN Manager authentication level incorrect #25

JCapriotti opened this issue Dec 6, 2018 · 1 comment

Comments

@JCapriotti
Copy link

Describe the bug
I may be unsure of the intent here, but windows-base-201 "Strong Windows NTLMv2 Authentication Enabled; Weak LM Disabled" is not set correctly according to CIS Windows 2012R2 and 2016. I'm not sure if the current implementation is for a different spec.

The CIS policy I'm referencing is:

2.3.11.7 (L1) Ensure 'Network security: LAN Manager authentication
level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM' 

Expected behavior
HKLM\System\CurrentControlSet\Control\Lsa:LmCompatibilityLevel should be set to 5

Actual behavior
HKLM\System\CurrentControlSet\Control\Lsa:LmCompatibilityLevel is set to 4

Inspec Version

1.51.21

Baseline Version

1c916e9
(master as of 2018-12-06)

Additional context
If the current implementation is correct, then I'm unsure of how to modify windows-baseline to support different specs for the same registry key. Any guidance would be helpful.

@atomic111
Copy link
Member

@JCapriotti it is fixed with the new baseline. Can I close it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants