Networking Forums

Networking Forums > Computer Networking > Windows Networking > 2 questions

Reply
 
 
Boris
Guest
Posts: n/a

 
      03-11-2010, 10:31 PM
Hi,

I'm not sure if my (below) questions would rather be asked on some other
newsgroup.

I have 2 questions on Domain Security Policy in Active Directory:

1. Is it possible to configure list of Windows Firewall exception rules (via
domain GPO) - and have those settings propagate to all client PCs?
2. There's NoLMHash setting in GPO - this prevents user passwords from being
stored using (weak) LMHash encryption. When this policy is set and new
passwords are created, they're no longer stored using LMHash encryption (but
rather using stronger NT encryption). However, this policy setting doesn't
apply retroactively: if some passwords were stored using LMHash before the
policy setting was applied, they will continue to be stored via LMHash even
after the policy setting was applied. Is there a way to force Windows
clients to recreate password hashes for existing passwords: so that
encryption method changed from LMHash to NTHash?

Thanks,
B.

 
Reply With Quote
 
 
 
 
Bob Lin \(MS-MVP\)
Guest
Posts: n/a

 
      03-12-2010, 12:43 AM
I am not sure the second question. You can setup Windows Firewall exception
rules in domain GPO. This post may help:
Windows Firewall Group Policy settings for the domain -
http://chicagotech.net/netforums/vie...69fbe240c5961e

--
Bob Lin, Microsoft-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com


"Boris" <(E-Mail Removed)> wrote in message
news:4b997d38$0$22092$(E-Mail Removed)...
> Hi,
>
> I'm not sure if my (below) questions would rather be asked on some other
> newsgroup.
>
> I have 2 questions on Domain Security Policy in Active Directory:
>
> 1. Is it possible to configure list of Windows Firewall exception rules
> (via domain GPO) - and have those settings propagate to all client PCs?
> 2. There's NoLMHash setting in GPO - this prevents user passwords from
> being stored using (weak) LMHash encryption. When this policy is set and
> new passwords are created, they're no longer stored using LMHash
> encryption (but rather using stronger NT encryption). However, this policy
> setting doesn't apply retroactively: if some passwords were stored using
> LMHash before the policy setting was applied, they will continue to be
> stored via LMHash even after the policy setting was applied. Is there a
> way to force Windows clients to recreate password hashes for existing
> passwords: so that encryption method changed from LMHash to NTHash?
>
> Thanks,
> B.


 
Reply With Quote
 
John John - MVP
Guest
Posts: n/a

 
      03-12-2010, 01:28 AM
Question #2: Just force a password change on the users and the LM
Hashes will be removed when they change their passwords. You can use
another GPO to force the password change.

John


Boris wrote:
> Hi,
>
> I'm not sure if my (below) questions would rather be asked on some other
> newsgroup.
>
> I have 2 questions on Domain Security Policy in Active Directory:
>
> 1. Is it possible to configure list of Windows Firewall exception rules
> (via domain GPO) - and have those settings propagate to all client PCs?
> 2. There's NoLMHash setting in GPO - this prevents user passwords from
> being stored using (weak) LMHash encryption. When this policy is set and
> new passwords are created, they're no longer stored using LMHash
> encryption (but rather using stronger NT encryption). However, this
> policy setting doesn't apply retroactively: if some passwords were
> stored using LMHash before the policy setting was applied, they will
> continue to be stored via LMHash even after the policy setting was
> applied. Is there a way to force Windows clients to recreate password
> hashes for existing passwords: so that encryption method changed from
> LMHash to NTHash?
>
> Thanks,
> B.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A few more questions regarding RIS Eric Windows Networking 0 02-27-2008 02:59 PM
VPN questions. steve Network Routers 0 07-22-2006 05:04 PM
mn-740 questions Anon Broadband Hardware 0 04-04-2004 05:57 PM
questions~ noricat Linux Networking 1 01-10-2004 02:32 PM
Questions Mcploppy © Broadband 15 08-14-2003 09:46 AM



1 2 3 4 5 6 7 8 9 10 11