Skip to content

PatchWalker 1.20.2

Choose a tag to compare

@jermainewalkes jermainewalkes released this 23 Jul 11:06

PatchWalker 1.20.2

Recommended for all Domain / gMSA installs. This is a focused stability fix.

Fixed

  • Machine key-store ACL corruption on gMSA upgrades. On a Domain (gMSA) Controller, the installer's certificate-import grant modified the shared, OS-protected MachineKeys folder with an inheritable ACL and re-applied it on every upgrade. On some machines this stripped SYSTEM and Administrators from the folder, making machine private keys unreadable and breaking the host's Remote Desktop (its listener certificate key). The grant now re-asserts SYSTEM and Administrators Full Control and no longer applies the damaging inheritable permission, while still allowing the service to import a TLS certificate from the web console. Standalone (LocalSystem) installs were never affected.
  • Recovery tool for already-affected machines. A repair script is installed at <install dir>\scripts\Repair-MachineKeysAcl.ps1. If an earlier version left a machine's key-store ACLs damaged, run it once from an elevated PowerShell to restore SYSTEM/Administrators access to the key files, then restart the Remote Desktop service (or reboot).
  • Seal-key permission grant is now idempotent - it no longer accumulates a duplicate entry on the TPM-sealed key each upgrade.

Install

Download PatchWalkerSetup-1.20.2.exe below and run it on the Controller. It upgrades in place over a running install and restarts the service. gMSA Controllers upgrading from an earlier version have SYSTEM/Administrators access to the machine key store re-asserted automatically as part of the upgrade.

SHA-256: f2b25f3494a855cf628ed9efbbfe43747ca5de29bff05843363276e66ecf0ef4