CCE-35263-3Platform: cpe:/o:microsoft:windows_8.1 | Date: (C)2015-10-14 (M)2023-07-04 |
Specify KDC proxy servers for Kerberos clients
This policy setting allows you to specify KDC proxy servers for DNS suffix names.
If you enable this policy setting, you can view and change the list of proxy servers configured for DNS suffix names as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a DNS suffix name. In the Value column, type the list of proxy servers using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.
If you disable or do not configure this policy setting, the Kerberos client does not have KDC proxy servers settings defined by Group Policy.
Parameter:
[]
Technical Mechanism:
(1) GPO: Computer Configuration\Administrative Templates\System\Kerberos!Specify KDC proxy servers for Kerberos clients
(2) REG: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos!KdcProxyServer_Enabled
CCSS Severity: | CCSS Metrics: |
CCSS Score : 6.4 | Attack Vector: ADJACENT_NETWORK |
Exploit Score: 1.6 | Attack Complexity: HIGH |
Impact Score: 4.7 | Privileges Required: NONE |
Severity: MEDIUM | User Interaction: NONE |
Vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H | Scope: UNCHANGED |
| Confidentiality: LOW |
| Integrity: LOW |
| Availability: HIGH |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:29772 |