Netlogon Hardening KB5021130

Matteo Montorsi 20 Reputation points
2023-03-24T10:49:20.98+00:00

Hi,

I'm checking an environment on which we have already done March 2023 updates on all DC's and enabled the registry key in Compatibility Mode.

From Event viewer I've found some Windows Server 2008 / 2008R2 that report Warning EventID 5840 "The Netlogon service created a secure channel with a client with RC4. "

What happen to these servers when MS enforce the hardening on NetLogon?

I'm wrong to think that we have to replace these machine before the next hardening step?

Thanks

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2023-03-24T12:34:26.3+00:00

    If you find Event 5840, this is a sign that a client in your domain is using weak cryptography. These ones below could help.

    https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2013/2868725?redirectedfrom=MSDN

    https://support.microsoft.com/en-us/topic/microsoft-security-advisory-update-for-disabling-rc4-479fd6f0-c7b5-0671-975b-c45c3f2c0540

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.