1.152 WN22-DC-000060

Information

Windows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less.

GROUP ID: V-254390
RULE ID: SV-254390r1051105

This setting determines the maximum time difference (in minutes) that Kerberos will tolerate between the time on a client's clock and the time on a server's clock while still considering the two clocks synchronous. To prevent replay attacks, Kerberos uses timestamps as part of its protocol definition. For timestamps to work properly, the clocks of the client and the server need to be in sync as much as possible.

Satisfies: SRG-OS-000112-GPOS-00057, SRG-OS-000113-GPOS-00058

Solution

Configure the policy value in the Default Domain Policy for

Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Maximum tolerance for computer clock synchronization to a maximum of '5' minutes or less

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(8), 800-53|IA-2(9), CAT|II, CCI|CCI-001941, CCI|CCI-001942, Rule-ID|SV-254390r1051105_rule, STIG-ID|WN22-DC-000060, Vuln-ID|V-254390

Plugin: Windows

Control ID: 570fd423729b2d1f238464a98415c84f480860cb9bc2f2a198dded80d4d603b9