Domain member: Digitally encrypt secure channel data (when possible)ID: oval:org.secpod.oval:def:18940 | Date: (C)2014-05-29 (M)2023-07-04 |
Class: COMPLIANCE | Family: windows |
The Domain member: Digitally encrypt secure channel data (when possible) setting should be configured correctly.
This policy setting determines whether a domain member should attempt to negotiate encryption for all secure channel traffic that it initiates. If you enable this policy setting, the domain member will request encryption of all secure channel traffic. If you disable this policy setting, the domain member will be prevented from negotiating secure channel encryption. Microsoft recommends to configure the Domain member: Digitally encrypt secure channel data (when possible) setting to Enabled.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Domain member: Digitally encrypt secure channel data (when possible)
(2) KEY: HKLM\System\CurrentControlSet\Services\Netlogon\Parameters\SealSecureChannel
Platform: |
Microsoft Windows Server 2008 R2 |