rbang
asked on
How should I disable the enablesecuritysignature? Use registry or GPO?
I'm having a single domain controller with Windows 2003 that also acts as a fileserver. I have the users grouped in several OU's with different GPO's assigned to each OU. I use GPO mainly to assign different login script's.
My problem is slow performance with the fileserver. I've read several discussions on this site about the enable- and requiresecuritysignature settings. I also see that these options are available through GPO's (if I hav eunderstood it correctly). Computer configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options and the "Microsoft Network Server: Digitally sign commun........
When i set these options in the GPO the speed increases but after rebooting a couple of times the client pc's loose contact with the fileserver.
If I set them in registry they are automatically set back to default after reboot?
Please help. Thanks in advance....
Roy
My problem is slow performance with the fileserver. I've read several discussions on this site about the enable- and requiresecuritysignature settings. I also see that these options are available through GPO's (if I hav eunderstood it correctly). Computer configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options and the "Microsoft Network Server: Digitally sign commun........
When i set these options in the GPO the speed increases but after rebooting a couple of times the client pc's loose contact with the fileserver.
If I set them in registry they are automatically set back to default after reboot?
Please help. Thanks in advance....
Roy
I always set it to off in both the Default Domain Controller and Default Domain GPO's
That said - I have had times it hasn't helped, and the fix is to set the NIC to fixed speed, not Auto Detect. This is on both 100mbit and 1Gbit switches...
That said - I have had times it hasn't helped, and the fix is to set the NIC to fixed speed, not Auto Detect. This is on both 100mbit and 1Gbit switches...
ASKER
I set it in the default domain policy.
The OU structure is very simple. Basically just creating a department structure under the domain root.
Domains - > kapp.local -> KNH (first OU) -> kappregnskap (child OU). The GPO in this OU has just a logon script.
Other settings regarding digitally signing is set in the default domain policy. Should I set it in the default domain controllers policy?
Thanks..
Roy
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
Should disabling it have anything to do with the client's ability to access the fileserver? I've had some problems with that. Could this problem be caused by only setting it on the DD level?
Roy
Roy
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Where are you applying this setting and in which GPO in OU ? It looks like in "Default Domain Policy" you have set "No Override" option.
What is your OU structure with GPO created?
Let me know.
Thanks