System objects: Require case insensitivity for non-Windows subsystemsID: oval:org.secpod.oval:def:35034 | Date: (C)2016-06-10 (M)2023-12-13 |
Class: COMPLIANCE | Family: windows |
This security setting determines whether case insensitivity is enforced for all subsystems. The Win32 subsystem is case insensitive. However, the kernel supports case sensitivity for other subsystems, such as POSIX.
If this setting is enabled, case insensitivity is enforced for all directory objects, symbolic links, and IO objects, including file objects. Disabling this setting does not allow the Win32 subsystem to become case sensitive.
Default: Enabled.
Counter Measure:
Enable the System objects: Require case insensitivity for non-Windows subsystems setting.
Potential Impact:
All subsystems will be forced to observe case insensitivity. This configuration may confuse users who are familiar with any UNIX-based operating systems that is case-sensitive.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\System objects: Require case insensitivity for non-Windows subsystems
(2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel!ObCaseInsensitive
Platform: |
Microsoft Windows 10 |