Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Is there a password filter file to download for WIndows server 2012 R2?

Posted on 2014-10-30
6
Medium Priority
?
2,008 Views
Last Modified: 2016-11-10
Hello,

As per one of the auditing reports, I am supposed to change the following registry key to include the file
EnPasFltV2x64

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\Noti
fication Packages.

The scan was performed on a test Windows 2012 R2 server.
I am unable to find this on Microsoft web site or may be there is none required for 2012. Though the report only says these are applicable to 2008 R2 servers, 2008 server etc but does not mention that it is applicable to Windows 2012 that the scan was done.

Am I missing something?

I could not find any solution to this on expert exchange too.

Please help.

The scan result is as follows:

Test Status Severity Time
Strong Password Filtering Failed 0 10/29/14 3:49
PM
Description This test verifies that strong password filtering is configured on this system. With this configu
ration, passwords must contain at least one lowercase letter, one uppercase letter, one num
ber, and one special character. Strong passwords help to protect a system from password
guessing attacks.
Rules Policy Registry Values
Element Equals (case insensitive) "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA|
Notification Packages"
Version conditions If an element version has no content, the condition should:Fail Regular expression: /\benp
asfltv2x(86|64)\b/ (Flags:Case insensitive) Notification Packages Exists

Thank you,
Lal_gs
0
Comment
Question by:lal_gs
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 40415076
it should still work remember to uncheck password complexity
Troubleshooting
0
 

Author Comment

by:lal_gs
ID: 40421772
Hello David,

Thanks for your reply. I have gone through the article that you sent through the link. But that article does not pertain to my question.

 For windows 2012 R2 servers, can I get a EnPasFltV2x64.dll? If so, where is it available.
 The article has not addressed this part.

We are trying  to enable "strong pasword filtering" for Windows 2012 R2 server.

Appreciate your help.

Thanks,

lal_gs
0
 
LVL 49

Expert Comment

by:dbrunton
ID: 40432028
See http://iase.disa.mil/stigs/os/windows/Pages/index.aspx

Read this first http://iase.disa.mil/stigs/os/windows/Documents/u_enpasflt_readme.txt

Warning!  Take care if you are unsure about what you are doing.
0
 
LVL 83

Accepted Solution

by:
David Johnson, CD, MVP earned 1500 total points
ID: 40433256
you can have one developed for you cheaply once you define your objectives properly.

The standard rules for password complexity are:

Passwords must contain characters from three of the following five categories:

1.    Uppercase characters of European languages (A through Z, with diacritic marks, Greek and Cyrillic characters)
2.    Lowercase characters of European languages (a through z, sharp-s, with diacritic marks, Greek and Cyrillic characters)
3.    Base 10 digits (0 through 9)
4.   Nonalphanumeric characters: ~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/
 5.    Any Unicode character that is categorized as an alphabetic character but is not uppercase or lowercase. This includes Unicode characters from Asian languages.

your pci checker requires 4 of the 5 which is even more than the DOD requirement.. If you have a DOD pki cert you can download the file from http://iase.disa.mil/stigs/os/windows/Pages/index.aspx
0
 

Expert Comment

by:Rick Baks
ID: 41881942
You might want to check out the product ActivePasswords. KISS and small, but very customizable!
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question