Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Networking > 2 questions

Reply
 
 
Boris
Guest
Posts: n/a

 
      03-11-2010
Hi,

I'm not sure if my (below) questions would rather be asked on some other
newsgroup.

I have 2 questions on Domain Security Policy in Active Directory:

1. Is it possible to configure list of Windows Firewall exception rules (via
domain GPO) - and have those settings propagate to all client PCs?
2. There's NoLMHash setting in GPO - this prevents user passwords from being
stored using (weak) LMHash encryption. When this policy is set and new
passwords are created, they're no longer stored using LMHash encryption (but
rather using stronger NT encryption). However, this policy setting doesn't
apply retroactively: if some passwords were stored using LMHash before the
policy setting was applied, they will continue to be stored via LMHash even
after the policy setting was applied. Is there a way to force Windows
clients to recreate password hashes for existing passwords: so that
encryption method changed from LMHash to NTHash?

Thanks,
B.

 
Reply With Quote
 
 
 
 
Bob Lin \(MS-MVP\)
Guest
Posts: n/a

 
      03-12-2010
I am not sure the second question. You can setup Windows Firewall exception
rules in domain GPO. This post may help:
Windows Firewall Group Policy settings for the domain -
http://chicagotech.net/netforums/vie...69fbe240c5961e

--
Bob Lin, Microsoft-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com


"Boris" <> wrote in message
news:4b997d38$0$22092$...
> Hi,
>
> I'm not sure if my (below) questions would rather be asked on some other
> newsgroup.
>
> I have 2 questions on Domain Security Policy in Active Directory:
>
> 1. Is it possible to configure list of Windows Firewall exception rules
> (via domain GPO) - and have those settings propagate to all client PCs?
> 2. There's NoLMHash setting in GPO - this prevents user passwords from
> being stored using (weak) LMHash encryption. When this policy is set and
> new passwords are created, they're no longer stored using LMHash
> encryption (but rather using stronger NT encryption). However, this policy
> setting doesn't apply retroactively: if some passwords were stored using
> LMHash before the policy setting was applied, they will continue to be
> stored via LMHash even after the policy setting was applied. Is there a
> way to force Windows clients to recreate password hashes for existing
> passwords: so that encryption method changed from LMHash to NTHash?
>
> Thanks,
> B.


 
Reply With Quote
 
John John - MVP
Guest
Posts: n/a

 
      03-12-2010
Question #2: Just force a password change on the users and the LM
Hashes will be removed when they change their passwords. You can use
another GPO to force the password change.

John


Boris wrote:
> Hi,
>
> I'm not sure if my (below) questions would rather be asked on some other
> newsgroup.
>
> I have 2 questions on Domain Security Policy in Active Directory:
>
> 1. Is it possible to configure list of Windows Firewall exception rules
> (via domain GPO) - and have those settings propagate to all client PCs?
> 2. There's NoLMHash setting in GPO - this prevents user passwords from
> being stored using (weak) LMHash encryption. When this policy is set and
> new passwords are created, they're no longer stored using LMHash
> encryption (but rather using stronger NT encryption). However, this
> policy setting doesn't apply retroactively: if some passwords were
> stored using LMHash before the policy setting was applied, they will
> continue to be stored via LMHash even after the policy setting was
> applied. Is there a way to force Windows clients to recreate password
> hashes for existing passwords: so that encryption method changed from
> LMHash to NTHash?
>
> Thanks,
> B.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Live ID Questions Richard Windows Live Mail 7 12-23-2009 12:37 AM
WLM Questions? R. Michael Windows Live Mail 3 11-05-2009 06:32 PM
Why don't MSI Installers Run in Elevated Context??? (And other deployment related questions) Joseph Geretz Windows Vista Installation 1 02-28-2007 09:45 PM
Simple contacts sync and certificate install questions Matt McComas ActiveSync 0 02-23-2007 03:14 PM
MSBLOG podcast questions Zack Whittaker Windows Vista General Discussion 0 04-15-2006 10:45 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59