Security risks by setting "IgnoreNoRevocationCheck = 1" on windows 10 clients

tn-57-gs 26 Reputation points
2021-08-02T13:14:41.827+00:00

Security risks by setting "IgnoreNoRevocationCheck = 1" on windows 10 clients
According to the below description [this article][1]. As per my understanding, clients will be allowed to connect even when client certificate does not have CRL Url. but what would be the case when "ignorenorevocationcheck"is set on clients registry EAP 13 & 25 but not on NPS or RRAS? I am pre-assuming from the description below, if NPS cannot complete revocation check still it allows the clients to connect. please correct me if I am wrong in understanding the concept here.

***> IgnoreNoRevocationCheck
When set to 1, NPS allows EAP-TLS clients to connect even when NPS does not perform or cannot complete a revocation check of the certificate chain (excluding the root certificate) of the client. Typically, revocation checks fail because the certificate does not include CRL information.

Blockquote***

on the other hand, what could be the security risks when we set the below registry on the clients computers.

Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\25 --> NoRootRevocationCheck --> 1

Authentication method used: Microsoft: Protected EAP (PEAP) and This is the [article I am referring to][1]:

Here is an overview about our environment

8 - RRAS --> Radius Authentication (2 NPS)
Clients - Windows 10 20H2

Devices are managed using Intune and client authentication (user certificate) from our PKI via NDES.

Below are the included/excluded steps during the implementation.

Due to security recommendation, skipped Step 7.1 (ignoring certification revocation on RRAS and NPS).

Skipped adding the below XML as well from Step 7.5 Procedure 3

Added "IgnoreNoRevocationCheck" under: "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13 & 25" on our managed clients

Steps (7.2 - 7.4) implemented with no difference to the above article.

Result: it is working after following the above steps but it would be much appreciated to know what could be a potential impact by ignoring revocation check from clients end. (1 possible known would be, the clients would fail to do CRL check). what are other security risks involved.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.