Discussion:
Microsoft Catch 22 RDP Update
Dave Crozier
2018-05-22 16:06:42 UTC
Permalink
Gentlemen,
Just had a 1 day full on panic here with the latest May 2018 update from Microsoft for Server 2008 and 2012. All the RDP (Remote desktop) sessions that used to connect now do NOT connect due to a change in the security settings on any client that has the latest Windows Updates.

This has caused us real grief as we run multiple remote sessions onto the VM’s on a 3 node cluster. Only one of the nodes on the cluster ran an automatic update along with a few of the VM’s and we found it made RDP access via either HyperV connect or standard RDP impossible:

“An Authentication error has occurred
The function requested is not supported/

Remote computer xx.xx.xx.xx
This could be due to CredSSP encryption oracle remediation.
For more information see https://go.microsoft.com/fwlink/?linkid=899990”

Nothing to do with oracle at all and all due to M$ updating security settings on a whim so as to mitigate the external code execution threat:

“CVE-2018-0886: "A remote code execution vulnerability exists in unpatched versions of CredSSP. An attacker who successfully exploits this vulnerability could relay user credentials to execute code on the target system. Any application that depends on CredSSP for authentication may be vulnerable to this type of attack."

The solution, should any of you encounter this error is to update the server as well as the clients the May 2018 update level, not simply the client or the server. Fortunately this was fairly easy as we migrated all the VM’s onto a spare node, upgraded the empty node and then migrated back and then connected to each VM via HyperV connect and did the 2018-05 updates.

At one stage we found ourselves unable to HyperV connect or RDP into any servers as our development machines are all updated automatically. Hence we were in a catch 22 situation….. Can’t connect to server in order to update the server, which would allow connection to the very server we couldn’t connect to. Thank god we had a spare cluster to migrate to!

All in all a totally wasted day as some of the retrograde updates took over 60 minutes per VM and we have about 20 of them. Oh Joy!

Thanks for the ‘heads up’ Mr Microsoft …. Where can I send the bill?

Dave Crozier
Software Development Manager
Flexipol Packaging Ltd.



---------------------------------------------------------------
This communication and the information it contains is intended for the person or organisation to whom it is addressed. Its contents are confidential and may be protected in law. If you have received this e-mail in error you must not copy, distribute or take any action in reliance on it. Unauthorised use, copying or disclosure of any of it may be unlawful. If you have received this message in error, please notify us immediately by telephone or email.

Flexipol Packaging Ltd. has taken every reasonable precaution to minimise the risk of virus transmission through email and therefore any files sent via e-mail will have been checked for known viruses. However, you are advised to run your own virus check before opening any
attachments received as Flexipol Packaging Ltd will not in any event accept any liability whatsoever once an e-mail and/or any attachment is received.

It is the responsibility of the recipient to ensure that they have adequate virus protection.

Flexipol Packaging Ltd.
Unit 14 Bentwood Road
Carrs
Industrial Estate
Haslingden
Rossendale
Lancashire
BB4 5HH

Tel:01706-222792
Fax: 01706-224683
www.Flexipol.co.uk
---------------------------------------------------------------

Terms & Conditions:

Notwithstanding delivery and the passing of risk in the goods, the property in the goods shall not pass to the buyer until the seller
Flexipol Packaging Ltd. ("The Company") has received in cash or cleared funds payment in full of the price of the goods and all other goods agreed to be sold by the seller to the buyer for which payment is then due. Until such time as the property in the goods passes to the buyer, the buyer shall hold the goods as the seller's fiduciary agent and bailee and keep the goods separate from those of the buyer and third parties and properly stored protected and insured and identified as the seller's property but shall be entitled to resell or use the goods in the ordinary course of its business. Until such time as the property in the goods passes to the buyer the seller shall be entitled at any time

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/***@EX2010-A-FPL.FPL.LOCAL
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for
Richard Kaye
2018-05-22 16:14:16 UTC
Permalink
Already had that fun the day the patch was released, Dave. Another temporary solution is to go into the Remote page of the System Properties on the RDP server and uncheck the box that says "Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended)".

You would think that MS would understand that servers don't get patched the same way as workstations but...
--
rk

-----Original Message-----
From: ProfoxTech <profoxtech-***@leafe.com> On Behalf Of Dave Crozier
Sent: Tuesday, May 22, 2018 12:07 PM
To: ***@leafe.com
Subject: Microsoft Catch 22 RDP Update

Gentlemen,
Just had a 1 day full on panic here with the latest May 2018 update from Microsoft for Server 2008 and 2012. All the RDP (Remote desktop) sessions that used to connect now do NOT connect due to a change in the security settings on any client that has the latest Windows Updates.

This has caused us real grief as we run multiple remote sessions onto the VM’s on a 3 node cluster. Only one of the nodes on the cluster ran an automatic update along with a few of the VM’s and we found it made RDP access via either HyperV connect or standard RDP impossible:

“An Authentication error has occurred
The function requested is not supported/

Remote computer xx.xx.xx.xx
This could be due to CredSSP encryption oracle remediation.
For more information see https://go.microsoft.com/fwlink/?linkid=899990”

Nothing to do with oracle at all and all due to M$ updating security settings on a whim so as to mitigate the external code execution threat:

“CVE-2018-0886: "A remote code execution vulnerability exists in unpatched versions of CredSSP. An attacker who successfully exploits this vulnerability could relay user credentials to execute code on the target system. Any application that depends on CredSSP for authentication may be vulnerable to this type of attack."

The solution, should any of you encounter this error is to update the server as well as the clients the May 2018 update level, not simply the client or the server. Fortunately this was fairly easy as we migrated all the VM’s onto a spare node, upgraded the empty node and then migrated back and then connected to each VM via HyperV connect and did the 2018-05 updates.

At one stage we found ourselves unable to HyperV connect or RDP into any servers as our development machines are all updated automatically. Hence we were in a catch 22 situation….. Can’t connect to server in order to update the server, which would allow connection to the very server we couldn’t connect to. Thank god we had a spare cluster to migrate to!

All in all a totally wasted day as some of the retrograde updates took over 60 minutes per VM and we have about 20 of them. Oh Joy!

Thanks for the ‘heads up’ Mr Microsoft …. Where can I send the bill?

Dave Crozier
Software Development Manager
Flexipol Packaging Ltd.



---------------------------------------------------------------
This communication and the information it contains is intended for the person or organisation to whom it is addressed. Its contents are confidential and may be protected in law. If you have received this e-mail in error you must not copy, distribute or take any action in reliance on it. Unauthorised use, copying or disclosure of any of it may be unlawful. If you have received this message in error, please notify us immediately by telephone or email.

Flexipol Packaging Ltd. has taken every reasonable precaution to minimise the risk of virus transmission through email and therefore any files sent via e-mail will have been checked for known viruses. However, you are advised to run your own virus check before opening any
attachments received as Flexipol Packaging Ltd will not in any event accept any liability whatsoever once an e-mail and/or any attachment is received.

It is the responsibility of the recipient to ensure that they have adequate virus protection.

Flexipol Packaging Ltd.
Unit 14 Bentwood Road
Carrs
Industrial Estate
Haslingden
Rossendale
Lancashire
BB4 5HH

Tel:01706-222792
Fax: 01706-224683
www.Flexipol.co.uk
---------------------------------------------------------------

Terms & Conditions:

Notwithstanding delivery and the passing of risk in the goods, the property in the goods shall not pass to the buyer until the seller
Flexipol Packaging Ltd. ("The Company") has received in cash or cleared funds payment in full of the price of the goods and all other goods agreed to be sold by the seller to the buyer for which payment is then due. Until such time as the property in the goods passes to the buyer, the buyer shall hold the goods as the seller's fiduciary agent and bailee and keep the goods separate from those of the buyer and third parties and properly stored protected and insured and identified as the seller's property but shall be entitled to resell or use the goods in the ordinary course of its business. Until such time as the property in the goods passes to the buyer the seller shall be entitled at any time

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/***@EX2010-A-FPL.FPL.LOCAL
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Report [OT] Abuse: http://leafe.com/reportAbuse/***@EX2010-A-FPL.FPL.LOCAL
_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/***@DM5PR10MB1244.namprd10.prod.outlook.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers
Fred Taylor
2018-05-22 16:17:02 UTC
Permalink
Yeah, that one bit me too. I think we ALL should submit invoices for our
time wasted on this. It might open their eyes! But I won't hold my breath
that they'll be more considerate of the impact of their "updates".


Fred
Post by Dave Crozier
Gentlemen,
Just had a 1 day full on panic here with the latest May 2018 update from
Microsoft for Server 2008 and 2012. All the RDP (Remote desktop) sessions
that used to connect now do NOT connect due to a change in the security
settings on any client that has the latest Windows Updates.
This has caused us real grief as we run multiple remote sessions onto the
VM’s on a 3 node cluster. Only one of the nodes on the cluster ran an
automatic update along with a few of the VM’s and we found it made RDP
“An Authentication error has occurred
The function requested is not supported/
Remote computer xx.xx.xx.xx
This could be due to CredSSP encryption oracle remediation.
For more information see https://go.microsoft.com/fwlink/?linkid=899990”
Nothing to do with oracle at all and all due to M$ updating security
“CVE-2018-0886: "A remote code execution vulnerability exists in unpatched
versions of CredSSP. An attacker who successfully exploits this
vulnerability could relay user credentials to execute code on the target
system. Any application that depends on CredSSP for authentication may be
vulnerable to this type of attack."
The solution, should any of you encounter this error is to update the
server as well as the clients the May 2018 update level, not simply the
client or the server. Fortunately this was fairly easy as we migrated all
the VM’s onto a spare node, upgraded the empty node and then migrated back
and then connected to each VM via HyperV connect and did the 2018-05
updates.
At one stage we found ourselves unable to HyperV connect or RDP into any
servers as our development machines are all updated automatically. Hence we
were in a catch 22 situation….. Can’t connect to server in order to update
the server, which would allow connection to the very server we couldn’t
connect to. Thank god we had a spare cluster to migrate to!
All in all a totally wasted day as some of the retrograde updates took
over 60 minutes per VM and we have about 20 of them. Oh Joy!
Thanks for the ‘heads up’ Mr Microsoft …. Where can I send the bill?
Dave Crozier
Software Development Manager
Flexipol Packaging Ltd.
---------------------------------------------------------------
This communication and the information it contains is intended for the
person or organisation to whom it is addressed. Its contents are
confidential and may be protected in law. If you have received this e-mail
in error you must not copy, distribute or take any action in reliance on
it. Unauthorised use, copying or disclosure of any of it may be unlawful.
If you have received this message in error, please notify us immediately by
telephone or email.
Flexipol Packaging Ltd. has taken every reasonable precaution to minimise
the risk of virus transmission through email and therefore any files sent
via e-mail will have been checked for known viruses. However, you are
advised to run your own virus check before opening any
attachments received as Flexipol Packaging Ltd will not in any event
accept any liability whatsoever once an e-mail and/or any attachment is
received.
It is the responsibility of the recipient to ensure that they have
adequate virus protection.
Flexipol Packaging Ltd.
Unit 14 Bentwood Road
Carrs
Industrial Estate
Haslingden
Rossendale
Lancashire
BB4 5HH
Tel:01706-222792
Fax: 01706-224683
www.Flexipol.co.uk
---------------------------------------------------------------
Notwithstanding delivery and the passing of risk in the goods, the
property in the goods shall not pass to the buyer until the seller
Flexipol Packaging Ltd. ("The Company") has received in cash or cleared
funds payment in full of the price of the goods and all other goods agreed
to be sold by the seller to the buyer for which payment is then due. Until
such time as the property in the goods passes to the buyer, the buyer shall
hold the goods as the seller's fiduciary agent and bailee and keep the
goods separate from those of the buyer and third parties and properly
stored protected and insured and identified as the seller's property but
shall be entitled to resell or use the goods in the ordinary course of its
business. Until such time as the property in the goods passes to the buyer
the seller shall be entitled at any time
[excessive quoting removed by server]

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/CAJCBksp3jAquh0hURj2j=***@mail.gmail.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the ob
Paul Hill
2018-05-22 17:46:16 UTC
Permalink
Post by Fred Taylor
Yeah, that one bit me too. I think we ALL should submit invoices for our
time wasted on this. It might open their eyes! But I won't hold my breath
that they'll be more considerate of the impact of their "updates".
Plenty of grief here today with the SMB2 thing (we advised sites to
disable SMB2 when Vista came out).
Still 300 or so legacy sites running our old xBase software.

Our support centre in Portugal (who are actually pretty good) aren't
trained in the old version.
There are only 2 guys here left that understand xBase. One has moved
into management.
Guess who has to support this?

Oh yeah, the Microsoft HTTPS/XML object (forget the name) doesn't
support TLS 1.1/1.2 on Windows 7.
One of our web booking providers is switching off older TLS versions tonight.

They've had plenty of notice and the new version came out in 2011.
Not my problem.
--
Paul

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/CADwx0+JzqVC8yLhK1QCEFp8z-***@mail.gmail.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Ted Roche
2018-05-22 19:26:53 UTC
Permalink
"Where Do You Want To Go Today?" (tm)
--
Ted Roche
Ted Roche & Associates, LLC
http://www.tedroche.com

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/CACW6n4sNzDKaRt4atDQ0YuexTo-3_mZLcNvFCK6s=***@mail.gmail.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Ken Dibble
2018-05-22 16:14:02 UTC
Permalink
Post by Dave Crozier
Just had a 1 day full on panic here with the latest May 2018 update
from Microsoft for Server 2008 and 2012. All the RDP (Remote
desktop) sessions that used to connect now do NOT connect due to a
change in the security settings on any client that has the latest
Windows Updates.
Dave, I feel your pain.

I've been following this issue, and waiting to see whether MS issued
a version of the patch that does not mess up NIC/DHCP addressing.

Did you have any issues with losing static internal IP addresses or
NIC settings on Server 2008?

Thanks.

Ken Dibble
www.stic-cil.org



_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Dave Crozier
2018-05-23 07:46:45 UTC
Permalink
Ken,
No problems I can see so far on NIC/DHCP addressing or static IP's changing.

Dave Crozier
Software Development Manager
Flexipol Packaging Ltd.



---------------------------------------------------------------
This communication and the information it contains is intended for the person or organisation to whom it is addressed. Its contents are confidential and may be protected in law. If you have received this e-mail in error you must not copy, distribute or take any action in reliance on it. Unauthorised use, copying or disclosure of any of it may be unlawful. If you have received this message in error, please notify us immediately by telephone or email.

Flexipol Packaging Ltd. has taken every reasonable precaution to minimise the risk of virus transmission through email and therefore any files sent via e-mail will have been checked for known viruses. However, you are advised to run your own virus check before opening any
attachments received as Flexipol Packaging Ltd will not in any event accept any liability whatsoever once an e-mail and/or any attachment is received.

It is the responsibility of the recipient to ensure that they have adequate virus protection.

Flexipol Packaging Ltd.
Unit 14 Bentwood Road
Carrs
Industrial Estate
Haslingden
Rossendale
Lancashire
BB4 5HH

Tel:01706-222792
Fax: 01706-224683
www.Flexipol.co.uk
---------------------------------------------------------------

Terms & Conditions:

Notwithstanding delivery and the passing of risk in the goods, the property in the goods shall not pass to the buyer until the seller
Flexipol Packaging Ltd. ("The Company") has received in cash or cleared funds payment in full of the price of the goods and all other goods agreed to be sold by the seller to the buyer for which payment is then due. Until such time as the property in the goods passes to the buyer, the buyer shall hold the goods as the seller's fiduciary agent and bailee and keep the goods separate from those of the buyer and third parties and properly stored protected and insured and identified as the seller's property but shall be entitled to resell or use the goods in the ordinary course of its business. Until such time as the property in the goods passes to the buyer the seller shall be entitled at any time

-----Original Message-----
From: ProFox <profox-***@leafe.com> On Behalf Of Ken Dibble
Sent: 22 May 2018 17:14
To: ***@leafe.com
Subject: Re: Microsoft Catch 22 RDP Update
Post by Dave Crozier
Just had a 1 day full on panic here with the latest May 2018 update
from Microsoft for Server 2008 and 2012. All the RDP (Remote
desktop) sessions that used to connect now do NOT connect due to a
change in the security settings on any client that has the latest
Windows Updates.
Dave, I feel your pain.

I've been following this issue, and waiting to see whether MS issued
a version of the patch that does not mess up NIC/DHCP addressing.

Did you have any issues with losing static internal IP addresses or
NIC settings on Server 2008?

Thanks.

Ken Dibble
www.stic-cil.org



_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/***@EX2010-A-FPL.FPL.LOCAL
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Ken Dibble
2018-05-23 14:20:15 UTC
Permalink
Thanks, Dave. Now if I can just figure out the logistics on this...
Post by Dave Crozier
Ken,
No problems I can see so far on NIC/DHCP addressing or static IP's changing.
Dave Crozier
Software Development Manager
Flexipol Packaging Ltd.
---------------------------------------------------------------
This communication and the information it contains is intended for
the person or organisation to whom it is addressed. Its contents are
confidential and may be protected in law. If you have received this
e-mail in error you must not copy, distribute or take any action in
reliance on it. Unauthorised use, copying or disclosure of any of it
may be unlawful. If you have received this message in error, please
notify us immediately by telephone or email.
Flexipol Packaging Ltd. has taken every reasonable precaution to
minimise the risk of virus transmission through email and therefore
any files sent via e-mail will have been checked for known viruses.
However, you are advised to run your own virus check before opening any
attachments received as Flexipol Packaging Ltd will not in any event
accept any liability whatsoever once an e-mail and/or any attachment
is received.
It is the responsibility of the recipient to ensure that they have adequate virus protection.
Flexipol Packaging Ltd.
Unit 14 Bentwood Road
Carrs
Industrial Estate
Haslingden
Rossendale
Lancashire
BB4 5HH
Tel:01706-222792
Fax: 01706-224683
www.Flexipol.co.uk
---------------------------------------------------------------
Notwithstanding delivery and the passing of risk in the goods, the
property in the goods shall not pass to the buyer until the seller
Flexipol Packaging Ltd. ("The Company") has received in cash or
cleared funds payment in full of the price of the goods and all
other goods agreed to be sold by the seller to the buyer for which
payment is then due. Until such time as the property in the goods
passes to the buyer, the buyer shall hold the goods as the seller's
fiduciary agent and bailee and keep the goods separate from those of
the buyer and third parties and properly stored protected and
insured and identified as the seller's property but shall be
entitled to resell or use the goods in the ordinary course of its
business. Until such time as the property in the goods passes to the
buyer the seller shall be entitled at any time
-----Original Message-----
Sent: 22 May 2018 17:14
Subject: Re: Microsoft Catch 22 RDP Update
Post by Dave Crozier
Just had a 1 day full on panic here with the latest May 2018 update
from Microsoft for Server 2008 and 2012. All the RDP (Remote
desktop) sessions that used to connect now do NOT connect due to a
change in the security settings on any client that has the latest
Windows Updates.
Dave, I feel your pain.
I've been following this issue, and waiting to see whether MS issued
a version of the patch that does not mess up NIC/DHCP addressing.
Did you have any issues with losing static internal IP addresses or
NIC settings on Server 2008?
Thanks.
Ken Dibble
www.stic-cil.org
[excessive quoting removed by server]

_______________________________________________
Post Messages to: ***@leafe.com
Subscription Maintenance: http://mail.leafe.com/mailman/listinfo/profox
OT-free version of this list: http://mail.leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Loading...