3.076 - The system is not configured to meet the minimum requirement for session security for NTLM SSP based Clients.

Information

Microsoft has implemented a variety of security support providers for use with RPC sessions. In a homogenous Windows environment, all of the options should be enabled and testing should be performed in a heterogeneous environment to determine the maximum-security level that provides reliable functionality.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'Network security- Minimum session security for NTLM SSP based (including secure RPC) clients' to 'Require NTLMv2 session security', 'Require 128-bit encryption' (all options selected).

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-15980r1_rule, STIG-ID|3.076, Vuln-ID|V-3382

Plugin: Windows

Control ID: 0c242abf78d9371114a9d8a70585b0a0ffafe08d364c2d4593cdc1efe7a7a2ab