NTLM handshake error using force updated clients option with the RDP applet
search cancel

NTLM handshake error using force updated clients option with the RDP applet

book

Article ID: 446784

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

You are getting this error using PAM RDP connection :

 

It can be bypassed by following this Technical Document  but then, by changing servers from Force Updated Clients to Mitigated, you would re-enable on compatibility with unpatched/vulnerable CredSSP clients. That preserves an attack path Microsoft and CIS recommend closing in hardened environments.

Cause

In present implementation of RDP access for PAM, there are two possible methods of logging in to remote workstations: RDP proxy and Applet.

The applet solution is based in freerdp, which does not have support for CredSSP-enabled devices. As a result it is not possible to enable Force updated clients option with the applet. 

At present the only way to be able to connect to this type of devices is by means of the RDP Proxy.

Resolution

As a replacement for the present applet-base implementation, an html5 solution is being developed and is now in the demo phase that relies on RDP Proxy and therefore overcomes present applet limitations.

Please check periodically for new features in future CA PAM releases