-
Patch side effects November updates – Domains only
Hat’s off to EP for spotting these:Addresses issues with Kerberos authentication related to the PerformTicketSignature registry subkey value in CVE-2020-17049, which was a part of the November 10, 2020 Windows update. The following issues might occur on writable and read-only domain controllers (DC) :
- Kerberos service tickets and ticket-granting tickets (TGT) might not renew for non-Windows Kerberos clients when PerformTicketSignature is set to 1 (the default).
- Service for User (S4U) scenarios, such as scheduled tasks, clustering, and services for line-of-business applications, might fail for all clients when PerformTicketSignature is set to 0.
- S4UProxy delegation fails during ticket referral in cross-domain scenarios if DCs in intermediate domains are inconsistently updated and PerformTicketSignature is set to 1.
The issue ONLY effects those with domains (businesses). It will not impact peer to peer or standalone computers. I expect to see more of these fixes for other platforms.
Spotted another one… https://support.microsoft.com/en-us/help/4594442 November 17, 2020—KB4594442 (OS Build 17763.1579) for 1809 Out-of-band (uh no that’s not an out of band patch for security the way I define out of band…)And more (thanks EP):KB4594441 for Win10 v1607:
https://support.microsoft.com/help/4594441KB4594443 for Win10 v1903 & 1909:
https://support.microsoft.com/help/4594443/KB4594440 for Win10 v2004 & 20H2:
https://support.microsoft.com/help/4594440/