Domain member: Digitally sign secure channel data (when possible)ID: oval:org.secpod.oval:def:56828 | Date: (C)2019-07-06 (M)2023-07-14 |
Class: COMPLIANCE | Family: windows |
This policy setting determines whether a domain member should attempt to negotiate whether all secure channel traffic that it initiates must be digitally signed. Digital signatures protect the traffic from being modified by anyone who captures the data as it traverses the network.
Microsoft recommends to configure the Domain member: Digitally sign secure channel data (when possible) setting to Enabled.
This policy setting determines whether a domain member should attempt to negotiate whether all secure channel traffic that it initiates must be digitally signed.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!Domain member: Digitally sign secure channel data (when possible)
(2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters!signsecurechannel
Platform: |
Microsoft Windows Server 2019 |