Warning: Windows update breaks authentication for some server admins
(2022/05/13)
- Reference: 1652396734
- News link: https://www.theregister.co.uk/2022/05/12/windows_server_update_authentication_errors/
- Source link:
Microsoft is warning a security update may cause authentication failures for Windows domain controllers.
"After installing updates released May 10, 2022 on your domain controllers, you might see authentication failures on the server or client for services such as Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP)," the IT goliath said in [1]an advisory published Wednesday.
The advisory refers to Windows update [2]KB5013943 (released Tuesday, May 10, 2022), which followed [3]KB5012643 (released April 25, 2022) and addresses a cause of screen flicker when starting in Safe Mode.
[4]
That April KB5012643 update was withdrawn from circulation on Wednesday, May 11, without explanation.
[5]
[6]
The latest Windows update, KB5013943, leaves unresolved issues in which some .NET Framework 3.5 apps [7]fail to open and some apps that use Direct3D 9 with certain GPUs crash (workarounds are suggested for both cases.)
The authentication difficulties should not affect client Windows devices or non-domain controller servers, according to Microsoft.
[8]
Netizens posting to /r/sysadmin on Reddit [9]noted the occurrence of authentication failures following the application of two Microsoft patches. Identified by the vulnerability ID [10]CVE-2022-26931 and [11]CVE-2022-26923 , the patches were intended to resolve two "high severity" privilege escalation vulnerabilities that are described in [12]KB5014754 .
Admins report Hyper-V and domain controller issues after first Patch Tuesday of 2022 [13]DEJA VU
"The long and the short of it is that attackers in certain privileged positions can mint certificates that impersonate other named principals," explained Steve Syfuhs, senior software engineer on the Windows Cryptography, Identity, and Authentication team at Microsoft, in [14]a Twitter post on Tuesday. "It's not a pants-on-fire situation because most environments already have mitigations in place that make this sort of attack difficult."
Syfuhs subsequently acknowledged that Microsoft is investigating reports of authentication problems.
"FYI we're aware of the NPS issue," he [15]said on Wednesday. "It's not related to NPS specifically but rather with how we're distinguishing between different kinds of names in the certificates. Only a subset of folks are affected by this."
In its advisory, Microsoft offered the following workaround: "The preferred mitigation for this issue is to [16]manually map certificates to a machine account in Active Directory."
[17]
If the preferred mitigation doesn't work, the IT behemoth suggests consulting KB5014754 for alternate strategies. At least one individual posting to /r/sysadmin [18]reports resolving the authentication problems by manually setting the CertificateMappingMethods SChannel registry key value on the domain controller to its former default setting, 0x1F . But others who claim to have tried this say their problems persist.
"We are presently investigating and will provide an update in an upcoming release," Microsoft's advisory says. ®
Get our [19]Tech Resources
[1] https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services
[2] https://support.microsoft.com/help/5013943
[3] https://support.microsoft.com/en-us/topic/april-25-2022-kb5012643-os-build-22000-652-preview-expired-43a75ee7-d857-4943-a2b9-f961538bd2b0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#some--net-framework-3-5-apps-might-have-issues
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.reddit.com/r/sysadmin/comments/um9qur/patch_tuesday_megathread_20220510/i85p2ll/?context=3
[10] https://nvd.nist.gov/vuln/detail/CVE-2022-26931
[11] https://nvd.nist.gov/vuln/detail/CVE-2022-26923
[12] https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16
[13] https://www.theregister.com/2022/01/13/microsoft_patch_tuesday_titsup/
[14] https://twitter.com/SteveSyfuhs/status/1524110040088518656?s=20
[15] https://twitter.com/SteveSyfuhs/status/1524570912275587072?s=20
[16] https://support.microsoft.com/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16#bkmk_certmap
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://www.reddit.com/r/sysadmin/comments/um9qur/patch_tuesday_megathread_20220510/i8c63f8/?context=3
[19] https://whitepapers.theregister.com/
"After installing updates released May 10, 2022 on your domain controllers, you might see authentication failures on the server or client for services such as Network Policy Server (NPS), Routing and Remote access Service (RRAS), Radius, Extensible Authentication Protocol (EAP), and Protected Extensible Authentication Protocol (PEAP)," the IT goliath said in [1]an advisory published Wednesday.
The advisory refers to Windows update [2]KB5013943 (released Tuesday, May 10, 2022), which followed [3]KB5012643 (released April 25, 2022) and addresses a cause of screen flicker when starting in Safe Mode.
[4]
That April KB5012643 update was withdrawn from circulation on Wednesday, May 11, without explanation.
[5]
[6]
The latest Windows update, KB5013943, leaves unresolved issues in which some .NET Framework 3.5 apps [7]fail to open and some apps that use Direct3D 9 with certain GPUs crash (workarounds are suggested for both cases.)
The authentication difficulties should not affect client Windows devices or non-domain controller servers, according to Microsoft.
[8]
Netizens posting to /r/sysadmin on Reddit [9]noted the occurrence of authentication failures following the application of two Microsoft patches. Identified by the vulnerability ID [10]CVE-2022-26931 and [11]CVE-2022-26923 , the patches were intended to resolve two "high severity" privilege escalation vulnerabilities that are described in [12]KB5014754 .
Admins report Hyper-V and domain controller issues after first Patch Tuesday of 2022 [13]DEJA VU
"The long and the short of it is that attackers in certain privileged positions can mint certificates that impersonate other named principals," explained Steve Syfuhs, senior software engineer on the Windows Cryptography, Identity, and Authentication team at Microsoft, in [14]a Twitter post on Tuesday. "It's not a pants-on-fire situation because most environments already have mitigations in place that make this sort of attack difficult."
Syfuhs subsequently acknowledged that Microsoft is investigating reports of authentication problems.
"FYI we're aware of the NPS issue," he [15]said on Wednesday. "It's not related to NPS specifically but rather with how we're distinguishing between different kinds of names in the certificates. Only a subset of folks are affected by this."
In its advisory, Microsoft offered the following workaround: "The preferred mitigation for this issue is to [16]manually map certificates to a machine account in Active Directory."
[17]
If the preferred mitigation doesn't work, the IT behemoth suggests consulting KB5014754 for alternate strategies. At least one individual posting to /r/sysadmin [18]reports resolving the authentication problems by manually setting the CertificateMappingMethods SChannel registry key value on the domain controller to its former default setting, 0x1F . But others who claim to have tried this say their problems persist.
"We are presently investigating and will provide an update in an upcoming release," Microsoft's advisory says. ®
Get our [19]Tech Resources
[1] https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services
[2] https://support.microsoft.com/help/5013943
[3] https://support.microsoft.com/en-us/topic/april-25-2022-kb5012643-os-build-22000-652-preview-expired-43a75ee7-d857-4943-a2b9-f961538bd2b0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#some--net-framework-3-5-apps-might-have-issues
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.reddit.com/r/sysadmin/comments/um9qur/patch_tuesday_megathread_20220510/i85p2ll/?context=3
[10] https://nvd.nist.gov/vuln/detail/CVE-2022-26931
[11] https://nvd.nist.gov/vuln/detail/CVE-2022-26923
[12] https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16
[13] https://www.theregister.com/2022/01/13/microsoft_patch_tuesday_titsup/
[14] https://twitter.com/SteveSyfuhs/status/1524110040088518656?s=20
[15] https://twitter.com/SteveSyfuhs/status/1524570912275587072?s=20
[16] https://support.microsoft.com/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16#bkmk_certmap
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn3X4wvXJUkAo5NsHjJlsgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://www.reddit.com/r/sysadmin/comments/um9qur/patch_tuesday_megathread_20220510/i8c63f8/?context=3
[19] https://whitepapers.theregister.com/
Cue the black helicopters
Trixr
They've almost succeeded with getting rid of on-prem Exchange with their diligent work on b0rked CUs in the last several years. Since November last year, they seem to be getting into high gear with stealth-deprecating Active Directory too.
I think every major AD-related update since then has had issues. And that's not counting Server 2022, every month's update for those seems to have something that screws up some AD-related service (me, to boss re deploying 2022 DCs: "NOT YET").
Zedexx
It's not related to NPS specifically... haha Yoy, again
/r/sysadmin
Either our industries standard canary in a coalmine or Microsoft's volunteer army of uncompensated QA and tech support depending on who you ask.
Remember, listen to others wails of pain before adding your own, and silence doth not equal success, for Redmond may have broken the TCP stack again, and the screams may have to wait till someone can hack together a working internet connection.