N2000H V3 Appliance
User Guide
5 System Security Policy
Issue 04 (2018-11-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies
Co., Ltd.
121
Configure encryption types allowed for Kerberos: DES_CBC_CRC,
DES_CBC_MD5, RC4_HMAC_MD5, AES128_HMAC_SHA1, Future
encryption types
Do not store LAN Manager password hash value on next password
change: Enabled
Force logoff when logon hours expire: Enabled
LAN Manager authentication level: Send NTLMv2 response only, refuse
LM & NTLM
LDAP client signing requirements: Negotiate signing
Minimum session security for NTLM SSP based (including secure RPC)
clients: Require NTLMv2 Session Security,Require 128-bit Encryption
Minimum session security for NTLM SSP based (including secure RPC)
servers: Require NTLMv2 Session Security,Require 128-bit Encryption
Recovery Console
Allow automatic administrative logon: Disabled
Allow floppy copy and access to all drives and all folders: Disabled
Shutdown
Allow system to be shutdown without having to log on: Disabled
System Objects
Require case insensitivity for non-Windows subsystems: Enabled
Strengthen default permissions of internal system objects: Enabled
User Account Control
Admin Approval Mode for the Built-in Administrator account: Enabled
Allow UIAccess applications to prompt for elevation without using the
secure desktop: Disabled
Behavior of the elevation prompt for administrators in Admin Approval
Mode: Prompt for credentials
Behavior of the elevation prompt for standard users: Prompt for
credentials
Detect application installations and prompt for elevation: Enabled
Only elevate UIAccess applications that are installed in secure locations:
Enabled
Switch to the secure desktop when prompting for elevation: Enabled
Virtualize file and registry write failures to per-user locations: Enabled
3)
Windows
Accessories
Windows Installer