What is the impact of CVE-2022-37966 to ONTAP 9
Applies to
- ONTAP 9
- CVE-2022-37966 - "Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability"
- Microsoft KB5021131
Answer
There is no known impact to ONTAP with regard to Kerberos authentication if the CIFS vserver was created in ONTAP 9
- ONTAP 9 by default when a cifs create is completed, sets the proper values for AD attribute msDS-SupportedEncryptionType
- Due to this, CVE-2022-37966 does not automatically default encryption to AES
Additional Information
- KB5021131
- In the event that msDS-SupportedEncryptionType is somehow suspected as not being set on the AD object, select one of the following KBs:
- As a best practice, and to ensure future changes have no impact, AES should be enabled on all SVMs
- RFE 1514688 CIFS AES should be on by default was created to enable AES by default
- This fix will only apply to new SVMs
- Existing SVMs will require AES to be enabled manually
- RFE 1514688 CIFS AES should be on by default was created to enable AES by default
- For information on impact to Data ONTAP 7-Mode, see KB: