Alert Type

PSN - Product Support Notification
MediumWindows Server administrators may not be the same team that manages network security devices. The update would impact services on the SRX and it may take some time to connect the dots back to this activity.
MediumWhen connectivity to the DC is severed, all user-identity based traffic will not be allowed through the firewall as SRX will lose visibility of who is authenticated.

Product Affected

This issue affects the following platforms: SRX-Series, NFX-Series

Alert Description

As part of the hardening changes made to DCOM,  recent Microsoft updates for newer Windows systems will enforce an Authentication-Level of RPC_C_AUTHN_LEVEL_PKT_INTEGRITY or higher for activation. This level will prevent the SRX from opening a WMI communication channel to patched systems unless the SRX is upgraded to a Junos release that supports it.

According to Microsoft KB5004442 [juniper.net] , the hardening changes will be enabled by default in Q1 2022. The changes can be disabled using a registry key. However, the hardening changes will be permanently enabled with no ability to disable them starting in Q2 2022.

To prevent impact to services provided by the Integrated User Firewall as a result of the hardening changes, actions are required on the SRX in the short and long term timelines.

Solution

The short term solution is to disable the hardening changes applied by the Microsoft Update. The steps, which involves changing the value of the registry key RequireIntegrityActivationAuthenticationLevel , can be found in Microsoft's KB article here:  https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c [juniper.net]

The longer term solution is to upgrade to a Junos release that will support the hardened authentication level. Please note that as per the KB article, Microsoft announced to remove the ability to disable the higher authentication level requirement in an update in Q2 of 2022. Therefore, a Junos upgrade is mandatory to ensure uninterrupted service with Integrated User Firewall (with AD integration) on the SRX.

For SRX300-series and SRX550M, the fix is available in Junos releases 20.2R3-S8, 20.4R3-S8, 21.2R3-S6, 22.4R3, 23.2R1 and higher releases. Please refer to PR-1683420 for the complete list.

For all other SRX and NFX platforms, the fix is available in Junos releases 19.4R3-S8, 20.4R3-S3, 21.2R3, 21.3R2, 21.4R2, 22.1R1 and higher releases. Please refer to PR-1637548  for the complete list.

FAQ:

Q: Will I need to patch the Windows Servers prior to upgrading to a Junos release that supports the higher authentication level?
A: It's not required. Windows already supports  RPC_C_AUTHN_LEVEL_PKT_INTEGRITY  regardless of whether that level is a prerequisite for opening a WMI channel. If the short term workaround (of disabling the hardening changes) is in effect, the administrator may reverse it to use the higher authentication level.

Q: Can I upgrade Junos to a fixed release before patching the Windows Servers?
A: Yes, you can. A fixed Junos release is able to interoperate with the Windows Servers regardless of their patch level and regardless if they enforce an Authentication-Level of RPC_C_AUTHN_LEVEL_PKT_INTEGRITY .

Q: Do I have to enable the hardening change on the Windows Servers after upgrade of Junos to a fixed release?
A: No, you do not have to. A fixed Junos release works fine regardless if the hardening change is enabled or disabled on the Windows Servers.
 

Modification History

2023-07-13: Updated TSB to add the PR1683420 fixed releases specifically for SRX Branch platforms.
2022-02-28: Updated TSB to reflect that the fix is available on the latest Junos releases.
2022-05-25: Added to the FAQ and updated the list of fixed releases.
 

Related Information