- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Microsoft Kerberos & NetLogon Changes November...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Microsoft Kerberos & NetLogon Changes November 8, 2022 Announcements
Does Checkpoint have any response with compatibility guidelines or issues regarding Microsoft's Kerberos & NetLogon changes announced today? See links below. Anything with Identity Awareness, Identity Connector, LDAP Lookup & VPN Authentication, etc...?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To the best of my knowledge, the only thing that MIGHT be impacted is transparent (browser) auth via Identity Awareness.
@Royi_Priov would know for sure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Identity Awareness Kerberos flows and AD-Query were analyzed and tested. No issues were found or reported.
We are still missing an indication on Microsoft side that configuration was applied correctly. We will try to verify it with Microsoft support.
Thanks,
Liel Shaish, RnD Group Manager
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good morning Liel, can you officially confirm that there are no potential issues?
Best regards
Emanuele
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are there any news regarding this issue ? How about SSO authentication via Kerberos with Identity Agent on windows machine ? Are we safe without changes ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Wolfgang, last week I opened a SR to Check Point support and this was their answer:
Official response from RnD:
According to the R & D team, CVE-2022-38023 and CVE-2022-37967 are part of Microsoft configuration (Kerberos server and windows server). Checkpoint gateways are not affected by these protocol changes. The only blade which listens to such traffic is Identity Awareness. The identity Awareness blade was analyzed and tested in response to Protocol Change CVE-2022-38023 and CVE-2022-37967 and no issues were found or reported
Regards
