{"id":798,"date":"2018-07-16T01:00:00","date_gmt":"2018-07-16T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/scvmm-blues-credssp\/"},"modified":"2018-07-16T01:00:00","modified_gmt":"2018-07-16T01:00:00","slug":"scvmm-blues-credssp","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/modern-workplace\/scvmm-blues-credssp\/","title":{"rendered":"SCVMM Blues (CredSSP)"},"content":{"rendered":"<h4 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\">The Day My Lab Died (CREDSSP Encryption Oracle Remediation)<\/h4>\n<p style=\"text-align: justify;\"><em>Mr. Praline: Look, matey, I know a dead parrot when I see one, and I\u2019m looking at one right now.<\/em><\/p>\n<p style=\"text-align: justify;\"><em>Owner: No no he\u2019s not dead, he\u2019s, he\u2019s restin\u2019!<\/em><\/p>\n<p style=\"text-align: justify;\">My lab died!<\/p>\n<p style=\"text-align: justify;\">It had been running quite happily for several weeks, then disaster struck\u2026<\/p>\n<p style=\"text-align: justify;\">Well to be precise (and a lot less dramatic), my<span>\u00a0<\/span><a href=\"https:\/\/docs.microsoft.com\/en-us\/system-center\/vmm\/?view=sc-vmm-1801\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft System Center Virtual Machine Manager<\/a>(SCVMM) lost the ability to control any of my Hyper-V clusters.<\/p>\n<p style=\"text-align: justify;\">I originally built this lab to prove a concept for a customer around a single instance of SCVMM,<span>\u00a0<\/span><a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/site-recovery\/\" rel=\"nofollow noopener\" target=\"_blank\">Azure Site Recovery<\/a><span>\u00a0<\/span>(ASR) and stretched subnets across two datacentres. You\u2019ll be able to read the results of this Proof of Concept (PoC) in another blog post (co-authored by Peter High).<\/p>\n<p style=\"text-align: justify;\">The primary error was:<\/p>\n<p style=\"text-align: justify;\"><span><em>Error (2912)<\/em><\/span><\/p>\n<p style=\"text-align: justify;\"><span><em>An internal error has occurred trying to contact the \u2018hyperv03.mydomain.corp\u2019 server: : .<\/em><\/span><\/p>\n<p style=\"text-align: justify;\"><span><em>WinRM: URL: [http:\/\/hyperv03.mydomain.corp:5985], Verb: [INVOKE], Method: [GetVersion], Resource: [http:\/\/schemas.microsoft.com\/wbem\/wsman\/1\/wmi\/root\/scvmm\/AgentManagement]<\/em><\/span><\/p>\n<p style=\"text-align: justify;\"><span><em>The request is not supported (0x80070032)<\/em><\/span><\/p>\n<p style=\"text-align: justify;\">Followed by recommendations to check that<span>\u00a0<\/span><a rel=\"noopener nofollow\" href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/aa384426(v=vs.85).aspx\" target=\"_blank\">Windows Remote Management<\/a><span>\u00a0<\/span>(WinRM) was running (it was) and that the SCVMM agent was installed on the Hyper-V host (it was).<\/p>\n<p style=\"text-align: justify;\">I went through the usual troubleshooting steps for WinRM:<\/p>\n<ol>\n<li>Test-WSMan \u2013 No errors<\/li>\n<li>Enable-PSRemoting \u2013 All good<\/li>\n<li>Enable-WSManCredSSP \u2013 No problems there<\/li>\n<li>Check local policy for \u2018Allow Delegating Fresh Credentials\u2019 \u2013 All set correctly<\/li>\n<li>cmd \u2013 No errors<\/li>\n<\/ol>\n<p style=\"text-align: justify;\">Then by chance, I searched using<span>\u00a0<\/span><a rel=\"noopener nofollow\" href=\"https:\/\/duckduckgo.com\/\" target=\"_blank\">DuckDuckGo<\/a><span>\u00a0<\/span>(privacy-focused search engine) for \u201cCredSSP the request is not supported\u201d and found the following article:<\/p>\n<p style=\"text-align: justify;\"><a rel=\"noopener nofollow\" href=\"https:\/\/www.tecklyfe.com\/how-to-fix-authentication-error-function-not-supported-credssp-error-rdp\/\" target=\"_blank\">https:\/\/www.tecklyfe.com\/how-to-fix-authentication-error-function-not-supported-credssp-error-rdp\/<\/a><\/p>\n<p style=\"text-align: justify;\">Microsoft released an update for CredSSP in March 2018 (CVE-2018-0886) which patches a known vulnerability that allows remote code execution (CredSSP encryption Oracle remediation). This fix was updated in May (last month).<\/p>\n<p style=\"text-align: justify;\"><a rel=\"noopener nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-0886\" target=\"_blank\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-0886<\/a><\/p>\n<p style=\"text-align: justify;\">The simplest solution is to patch all servers immediately, but as we all know, patching takes time, and in a production environment with mandated maintenance windows, it takes planning.<\/p>\n<p style=\"text-align: justify;\">A short-term workaround is available. Set the Group Policy value for \u201cComputer Configuration\/Administrative Templates\/System\/Credentials Delegation\/Encrypted Oracle Remediation\u201d to \u2018Vulnerable\u2019.<\/p>\n<p style=\"text-align: justify;\"><strong>Note:<\/strong><span>\u00a0<\/span>Make sure that you understand the impact of setting this value which is detailed here:<\/p>\n<p style=\"text-align: justify;\"><a rel=\"noopener nofollow\" href=\"https:\/\/support.microsoft.com\/en-us\/help\/4093492\/credssp-updates-for-cve-2018-0886-march-13-2018\" target=\"_blank\">https:\/\/support.microsoft.com\/en-us\/help\/4093492\/credssp-updates-for-cve-2018-0886-march-13-2018<\/a><\/p>\n<p style=\"text-align: justify;\">Now that all my servers are patched, SCVMM is happily talking to my Hyper-V clusters.<\/p>\n<p style=\"text-align: justify;\">I was lucky \u2013 \u00a0this only impacted a lab. Imagine if this was your production environment?<\/p>\n<p style=\"text-align: justify;\">While it\u2019s great that Microsoft is providing regular fixes for issues and bugs, it is a timely reminder that installing patches is not without some risk.<\/p>\n<p style=\"text-align: justify;\">Ironically as my Practice Manager proofread this blog post, he realised that it would fix his issue with accessing his Virtual Machine in Azure!<\/p>\n<p style=\"text-align: justify;\"><em>Mr. Praline: Now that\u2019s what I call a dead parrot.<\/em><\/p>\n<p style=\"text-align: justify;\"><em>Owner: No, no\u2026..No, \u2018e\u2019s stunned!<\/em><\/p>\n<p style=\"text-align: justify;\"><em>Mr. Praline: STUNNED?!?<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Day My Lab Died (CREDSSP Encryption Oracle Remediation) Mr. Praline: Look, matey, I know a dead parrot when I see one, and I\u2019m looking at one right now. Owner: No no he\u2019s not dead, he\u2019s, he\u2019s restin\u2019! My lab died! It had been running quite happily for several weeks, then disaster struck\u2026 Well to&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/modern-workplace\/scvmm-blues-credssp\/\">Continue reading <span class=\"screen-reader-text\">SCVMM Blues (CredSSP)<\/span><\/a><\/p>\n","protected":false},"author":88,"featured_media":799,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-798","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/88"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=798"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/798\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/799"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}