WN16-SO-000190 - The setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB client will only communicate with an SMB server that performs SMB packet signing.

Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000424-GPOS-00188

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Microsoft network client: Digitally sign communications (always)' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2016_V2R5_STIG.zip

Item Details

References: CAT|II, CCI|CCI-002418, CCI|CCI-002421, Rule-ID|SV-225039r852383_rule, STIG-ID|WN16-SO-000190, STIG-Legacy|SV-88317, STIG-Legacy|V-73653, Vuln-ID|V-225039

Plugin: Windows

Control ID: ff44ddbfc3bf76896dce4661bf62760d9d5c67e7241913f8e9c92461e2781a83