Domain member: Digitally encrypt secure channel data (when possible)ID: oval:org.secpod.oval:def:22874 | Date: (C)2015-01-07 (M)2023-07-31 |
Class: COMPLIANCE | Family: windows |
This policy setting determines whether a domain member should attempt to negotiate encryption for all secure channel traffic that it initiates. If you enable this policy setting, the domain member will request encryption of all secure channel traffic. If you disable this policy setting, the domain member will be prevented from negotiating secure channel encryption.
Microsoft recommends to configure the Domain member: Digitally encrypt secure channel data (when possible) setting to Enabled.
This policy setting determines whether a domain member should attempt to negotiate encryption for all secure channel traffic that it initiates.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!Domain member: Digitally encrypt secure channel data (when possible)
(2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters!sealsecurechannel
Platform: |
Microsoft Windows Server 2012 R2 |