SV-205820r569188_rule
V-205820
SRG-OS-000423-GPOS-00187
WN19-DC-000320
CAT II
10
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain controller: LDAP server signing requirements" to "Require signing".
This applies to domain controllers. It is NA for other systems.
If the following registry value does not exist or is not configured as specified, this is a finding:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SYSTEM\CurrentControlSet\Services\NTDS\Parameters\
Value Name: LDAPServerIntegrity
Value Type: REG_DWORD
Value: 0x00000002 (2)
V-205820
False
WN19-DC-000320
This applies to domain controllers. It is NA for other systems.
If the following registry value does not exist or is not configured as specified, this is a finding:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SYSTEM\CurrentControlSet\Services\NTDS\Parameters\
Value Name: LDAPServerIntegrity
Value Type: REG_DWORD
Value: 0x00000002 (2)
M
2907