Domain member: Digitally sign secure channel data (when possible)ID: oval:org.secpod.oval:def:18733 | Date: (C)2014-05-29 (M)2023-07-14 |
Class: COMPLIANCE | Family: windows |
The Domain member: Digitally sign secure channel data (when possible) setting should be configured correctly.
This policy setting determines whether a domain member should attempt to negotiate whether all secure channel traffic that it initiates must be digitally signed. Digital signatures protect the traffic from being modified by anyone who captures the data as it traverses the network. Microsoft recommends to configure the Domain member: Digitally sign secure channel data (when possible) setting to Enabled.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Domain member: Digitally sign secure channel data (when possible)
(2) KEY: HKLM\System\CurrentControlSet\Services\Netlogon\Parameters\SignSecureChannel
Platform: |
Microsoft Windows Server 2008 R2 |