Skip to main content

Problems with Vista and NAS boxes

HISTORY
In the old days Microsoft used to used to encrypt user name and password challenges and responses between clients and servers using LM (LAN Manager). This was then updated to NTLM (NT LAN Manager) which offered greater resistance to hacking. SAMBA, the SMB client/server system used by Linux and, consequently, most NAS boxes generally supports both of these protocols when you try and login from a Windows client machine.

PROBLEM
However, the more recent and secure NTLMv2 is not generally supported by most NAS boxes. Consequently, a client attempting to login using NTLMv2 will not be able to access the NAS since it's responses will not be understood by the NAS.

Window 2000 (SP4) and XP support NTLMv2 but do not make it mandatory. Unfortunately, good old Windows Vista now defaults to send "NTLMv2 Response Only" which means that many NAS boxes will not be able to authenticate the Windows Vista client.

SOLUTION
The way to fix this is to configure Vista so that it can still use NTLMv2 but only if negotiated, therefore using either LM or NTLM otherwise. Now the NAS box will be able to authenticate the client since it speaks the lingo.

The following steps detail the process:

1. Click Start menu Run then type "secpol.msc"
a. Note: Run is not in the Vista start menu by default and can be put there by right clicking
the menu choosing Properties then Start Menu tab then Customize and ticking "Run
command"
b. Alternatively just hold the Windows Logo or Start button on your keyboard and the hit
the Pause/Break key

2. In the Local Security Policy editor navigate to: Security Settings Local Policy Security Options and double click the "Network Security: LAN Manager authentication level Properties" policy

3. Click the drop-down menu and choose "Send LM & NTLM - use NTLMv2 session security if negotiated", click "Ok", and then close the Local Security Policy editor

You should now be able to logon to your NAS box with the correct username and password.

For more information see the Microsoft knowledgebase item below:

http://support.microsoft.com/kb/823659

Comments

Unknown said…
The Security Policy Editor is not present in Vista Home - one must edit the registry instead.
Remember to back up the registry BEFORE editing it.
1. Run REGEDIT
2. Find LSA
3. Modify LmCompatibilityLevel by changing the "3" value to "1"
4. Exit REGEDIT
Anonymous said…
Really cool blog brother. I've been coming here for quite some time, but I've never commented before. This blog is a constant inspiration like my prefer book Thanks for sharing so much. Buy Viagra
Viagra said…
I agree with this because the best solution of this configuring Vista so that it can still use NTLMv2.
Thanks mate... just dropped by. Will look for BIKE STN when we get to Seattle. Still in Buenos Airies.

Popular posts from this blog

Resolve WSUS Server issue that gives "Cannot save configuration because the server is still processing"

This is a pretty infuriating error and can sometimes crop up as a result of running a "wsusutil reset" command. First of all, give the server some time, and then a bit more...  but you've probably already done this. These steps may help to resolve the situation: - Install Microsoft SQL Management Studio (free download) - Run SQL Management Studio and start to connect to the WSUS database - Enter this in the "Server Name" box:  \\.\pipe\MICROSOFT##WID\tsql\query - Expand the "Databases" tree - Right-click on "SUSDB" and choose "New Query" - Paste this query in:     UPDATE tbSingletonData     SET ResetStateMachineNeeded = 0 - You should see a message like "1 row affected", which is good - Quit SQL Management Studio - Open "Services" and restart the "WSUS Service" - Now, open WSUS

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Jamf Pro DEP Enrollment Sync failed: Communication error. Awaiting next sync

 This error catches me out every so often when a customer of mine gets new iPads and I have to enrol them.  It's often been some time since I've last done this job and sometimes the MDM Server token needs to be refreshed (for want of a better term) before sync can re-commence between Apple School Manager and the customer's MDM (in this case Jamf Pro). Here are the list of steps to take: Log in to Apple School Manager (ASM) in one browser tab, and your MDM in another tab. In ASM, click your account name on the bottom left, and click "Preferences". Under "Device Management Services" click on your MDM service (Jamf Pro in my case). Click "Download Token" and allow the p7m file to download. In your MDM service, you'll need to upload the p7m file into its "Server token file" area. In Jamf Pro, click into "Settings" and then go into "Automated device enrollment", which is in the "Global Management" area. Cl...