Microsoft Security Baselines Blog

Learn more:  aka.ms/baselines    |    Download the Security Compliance Toolkit:  aka.ms/SCT

Options
2,511
Rick_Munck on Jun 14 2024 07:22 AM
3,107
Rick_Munck on May 20 2024 08:03 AM
3,792
Rick_Munck on Apr 26 2024 02:09 PM
4,127
Rick_Munck on Mar 27 2024 08:22 AM
5,459
Rick_Munck on Mar 01 2024 06:14 AM
7,334
Rick_Munck on Feb 14 2024 08:19 AM
11.6K
Rick_Munck on Dec 14 2023 05:19 PM
11.5K
Rick_Munck on Dec 14 2023 03:39 PM
12.4K
Rick_Munck on Nov 10 2023 06:36 AM
51K
Rick_Munck on Oct 31 2023 10:09 AM
12.1K
Rick_Munck on Oct 15 2023 02:42 PM
16.4K
Rick_Munck on Sep 18 2023 01:24 PM
11.9K
Rick_Munck on Aug 21 2023 02:51 PM
12.4K
Rick_Munck on Jul 24 2023 08:08 AM
20.1K
Rick_Munck on Jun 29 2023 07:00 AM
19.4K
Rick_Munck on Jun 05 2023 10:55 AM
14.5K
Rick_Munck on May 06 2023 06:19 AM
15.7K
Rick_Munck on Apr 07 2023 06:00 AM
12K
Rick_Munck on Mar 14 2023 05:33 AM
13.5K
Rick_Munck on Feb 13 2023 05:18 AM
14.8K
Rick_Munck on Jan 17 2023 06:01 AM
19.4K
Rick_Munck on Dec 06 2022 06:47 PM
14.6K
Rick_Munck on Nov 17 2022 12:59 PM
60.1K
Rick_Munck on Oct 18 2022 10:10 AM
11.7K
Rick_Munck on Oct 04 2022 09:00 AM
231K
Rick_Munck on Sep 20 2022 10:01 AM
11.6K
Rick_Munck on Sep 02 2022 08:00 AM
13K
Rick_Munck on Aug 08 2022 08:30 AM
16.1K
Rick_Munck on Jun 24 2022 07:37 AM
27.2K
Rick_Munck on Jun 14 2022 09:13 AM

Latest Comments

@KrisP120 - but why waste time and effort with pushing out that script when the simple Enabled/Disabled setting in the "MS Security Guide" ADMX does it correctly (and more sensibly)?
3 Likes
@mdeklavon : Please try to deploy the below script forcing type REG_SZ instead of DWORD on both the nodes to mitigate CVE-2013-3900.# Specify the registry path and values$registryPath = "HKLM:\Software\Microsoft\Cryptography\Wintrust\Config"$registryValues = @{"EnableCertPaddingCheck" = "1"} # Set t...
0 Likes
@AaronMargosis_Tanium, thank you so much for the extra information and explaining how Windows processes the data! Seeing Microsoft insist in multiple documents that it is REG_SZ had me thinking something in the backend required it. This is what I get for not testing. Thank you for helping me us the ...
0 Likes
@mdeklavon : EnableCertPaddingCheck should be a REG_DWORD. MSRC's documentation should be corrected; I submitted the information below to MSRC, but so far they've decided to take no action. Insisting that the value is a REG_SZ is the suboptimal path. I did a bunch of testing and I found that Windows...
2 Likes
Any update on when EnableCertPaddingCheck will be updated to be REG_SZ instead of DWORD? <policy name="Pol_SecGuide_Certificate_Padding" class="Machine" displayName="$(string.Pol_SecGuide_CertPadding)" explainText="$(string.Pol_SecGuide_CertPadding_Help)" key="Software\Microsoft\Cryptography\Wintrus...
0 Likes