Skip to main content
CUI

Vulnerability V-243476

Back

V-243476

CAT II

All accounts, privileged and unprivileged, that require smart cards must have the underlying NT hash rotated at least every 60 days.

Ships Affected
1
Total Findings
1
Open
0
Closed
1

Check Text

Windows Server 2016 with a domain functional level of Windows Server 2016: Open "Active Directory Administrative Center". Right-click on the domain name and select "Properties". If the "Domain functional level:" is not "Windows Server 2016", another method must be used to reset the NT hashes. See below for other options. If the "Domain functional level:" is "Windows Server 2016" and "Enable rolling of expiring NTLM secrets during sign on, for users who are required to use Microsoft Passport or smart card for interactive sign on" is not checked, this is a finding. Active Directory domains with a domain functional level below Windows Server 2016: Verify the organization rotates the NT hash for smart card-enforced accounts every 60 days. This can be accomplished with the use of scripts. DOD PKI-PKE has provided a script under PKI and PKE Tools at https://cyber.mil/pki-pke/tools-configuration-files/. Refer to the User Guide for additional information. NSA has also provided a PowerShell script with Pass-the-Hash guidance at https://github.com/nsacyber/Pass-the-Hash-Guidance. Running the "Invoke-SmartcardHashRefresh" cmdlet in the "PtHTools" module will trigger a change of the underlying NT hash. Refer to the site for additional information. Manually rolling the NT hash requires disabling and reenabling the "Smart Card required for interactive logon" option for each smart card-enforced account, which is not practical for large groups of users. If NT hashes for smart card-enforced accounts are not rotated every 60 days, this is a finding.

Fix Text

Windows Server 2016 with domain functional levels of Windows Server 2016: Open "Active Directory Administrative Center". Right-click on the domain name and select "Properties". Select "Enable rolling of expiring NTLM secrets during sign on, for users who are required to use Microsoft Passport or smart card for interactive sign on". Active Directory domains not at a Windows Server 2016 domain functional level: Rotate the NT hash for smart card-enforced accounts every 60 days. This can be accomplished with the use of scripts. DOD PKI-PKE has provided a script under PKI and PKE Tools at https://cyber.mil/pki-pke/tools-configuration-files/. Refer to the User Guide for additional information. NSA has also provided a PowerShell script with Pass-the-Hash guidance at https://github.com/nsacyber/Pass-the-Hash-Guidance. Running the "Invoke-SmartcardHashRefresh" cmdlet in the "PtHTools" module will trigger a change of the underlying NT hash. Refer to the site for additional information. Manually rolling the NT hash requires disabling and reenabling the "Smart Card required for interactive logon" option for each smart card-enforced account, which is not practical for large groups of users.

STIG Reference

STIG
Active Directory Domain Security Technical Implementation Guide
Version
3
Release
7
Rule ID
SV-243476r1038967_rule

All Occurrences

This vulnerability appears on 1 ship(s)

Ship Hull # Source File Status Assigned To Scan Date Actions
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-DC-003/Checklist/MONT-DC-003_ADDomain_V3R5_20251023-171837.ckl
Unassigned 2026-01-14T12:57:36.435963 View in Context
CUI