SV-271427r1137691_rule
V-271427
SRG-OS-000080-GPOS-00048
WN22-DC-000406
CAT II
10
Configure the policy value for Computer Configuration >> Administrative Template >> System >> KDC >> Allow name-based strong mappings for certificates to "Enabled".
This applies to domain controllers. This is not applicable for member servers.
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Administrative Template >> System >> KDC >> Allow name-based strong mappings for certificates.
If "Allow name-based strong mappings for certificates" is not "Enabled", this is a finding.
V-271427
False
WN22-DC-000406
This applies to domain controllers. This is not applicable for member servers.
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Administrative Template >> System >> KDC >> Allow name-based strong mappings for certificates.
If "Allow name-based strong mappings for certificates" is not "Enabled", this is a finding.
M
5485