Skip to main content

Problems with Vista and NAS boxes

HISTORY
In the old days Microsoft used to used to encrypt user name and password challenges and responses between clients and servers using LM (LAN Manager). This was then updated to NTLM (NT LAN Manager) which offered greater resistance to hacking. SAMBA, the SMB client/server system used by Linux and, consequently, most NAS boxes generally supports both of these protocols when you try and login from a Windows client machine.

PROBLEM
However, the more recent and secure NTLMv2 is not generally supported by most NAS boxes. Consequently, a client attempting to login using NTLMv2 will not be able to access the NAS since it's responses will not be understood by the NAS.

Window 2000 (SP4) and XP support NTLMv2 but do not make it mandatory. Unfortunately, good old Windows Vista now defaults to send "NTLMv2 Response Only" which means that many NAS boxes will not be able to authenticate the Windows Vista client.

SOLUTION
The way to fix this is to configure Vista so that it can still use NTLMv2 but only if negotiated, therefore using either LM or NTLM otherwise. Now the NAS box will be able to authenticate the client since it speaks the lingo.

The following steps detail the process:

1. Click Start menu Run then type "secpol.msc"
a. Note: Run is not in the Vista start menu by default and can be put there by right clicking
the menu choosing Properties then Start Menu tab then Customize and ticking "Run
command"
b. Alternatively just hold the Windows Logo or Start button on your keyboard and the hit
the Pause/Break key

2. In the Local Security Policy editor navigate to: Security Settings Local Policy Security Options and double click the "Network Security: LAN Manager authentication level Properties" policy

3. Click the drop-down menu and choose "Send LM & NTLM - use NTLMv2 session security if negotiated", click "Ok", and then close the Local Security Policy editor

You should now be able to logon to your NAS box with the correct username and password.

For more information see the Microsoft knowledgebase item below:

http://support.microsoft.com/kb/823659

Comments

Unknown said…
The Security Policy Editor is not present in Vista Home - one must edit the registry instead.
Remember to back up the registry BEFORE editing it.
1. Run REGEDIT
2. Find LSA
3. Modify LmCompatibilityLevel by changing the "3" value to "1"
4. Exit REGEDIT
Anonymous said…
Really cool blog brother. I've been coming here for quite some time, but I've never commented before. This blog is a constant inspiration like my prefer book Thanks for sharing so much. Buy Viagra
Viagra said…
I agree with this because the best solution of this configuring Vista so that it can still use NTLMv2.
Thanks mate... just dropped by. Will look for BIKE STN when we get to Seattle. Still in Buenos Airies.

Popular posts from this blog

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Copying NTFS Permissions with RichCopy

 Microsoft's RichCopy is a fantastic tool for copying/moving files.  It's multithreaded so moves things along quicker and has a nice log so you can see what's working and what's going wrong. It's kind of like a GUI on top of RoboCopy and you can get it here... However, I always forget that it doesn't copy file/folder NTFS permissions by default.  This is what you need to do if you want permissions to copy across to the destination: - Click the "View" menu and then click on "Advanced". - Then click the "Option" button on the right below the "Source" and "Destination" buttons. - Click on "File attributes, Error Handling" - Tick the relevant boxes under the "Security information" section. Hope this helps.

XP Startup Issues - The Recovery Console

The Windows Recovery Console is a fantastically useful tool if you find yourself with a PC that will not boot Windows. There are many useful Windows startup tools such as Last Known Good Configuration and the many different flavours of Safe Mode but all of these rely on a bootable Windows system. System Restore is completely useless in this scenario since it relies on one being in Windows to use it. The kinds of things that could couse an unbootable Windows system could be: Corrupted boot files - e.g. NTLDR, NTDETECT.COM Corrputed Windows system files - NTOSKRNL.EXE, HAL.DLL The Recovery Console allows you to boot into an environment "underneath" that of your Windows installation (by using the Windows CD or by choosing it at boot time if you pre-installed it) and so you can perform major low level repairs to your Windows installation. Follow the link below to find out how to use the Recovery Console: http://support.microsoft.com/kb/314058/