Check: WN08-SO-000061
Windows 8/8.1 STIG:
WN08-SO-000061
(in versions v1 r23 through v1 r16)
Title
Services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity vs. authenticating anonymously. (Cat II impact)
Discussion
Services using Local System that use Negotiate when reverting to NTLM authentication may gain unauthorized access if allowed to authenticate anonymously vs. using the computer identity.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. (See "Performing Analysis with the Security Configuration and Analysis Snap-in" in the STIG Overview document.) Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for "Network Security: Allow Local System to use computer identity for NTLM" is not set to "Enabled", this is a finding. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \System\CurrentControlSet\Control\LSA\ Value Name: UseMachineId Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "Network Security: Allow Local System to use computer identity for NTLM" to "Enabled".
Additional Identifiers
Rule ID: SV-48419r2_rule
Vulnerability ID: V-21951
Group Title: Computer Identity Authentication for NTLM
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000778 |
Uniquely identify organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection. |
Controls
Number | Title |
---|---|
IA-3 |
Device Identification and Authentication |