|Platform: win2012r2||Date: (C)2015-10-08 (M)2017-10-31|
Microsoft network client: Digitally sign communications (if server agrees)
This policy setting determines whether the SMB client will attempt to negotiate SMB packet signing. The implementation of digital signing in Windows?based networks helps to prevent sessions from being hijacked. If you enable this policy setting, the Microsoft network client will use signing only if the server with which it communicates accepts digitally signed communication.
Microsoft recommends to enable The Microsoft network client: Digitally sign communications (if server agrees) setting.
Note Enabling this policy setting on SMB clients on your network makes them fully effective for packet signing with all clients and servers in your environment.
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options!Microsoft network client: Digitally sign communications (if server agrees)
(2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters!EnableSecuritySignature
|SCAP Repo OVAL Definition||oval:org.secpod.oval:def:22934|