Microsoft warned that starting with this week's optional preview updates, temporary mitigation provided one year ago to address Windows Server printing issues on non-compliant devices will be removed, potentially breaking printing.
As Redmond explained last year, a known issue might cause print and scan failures on multiple Windows Server versions after installing the July 2021 security updates on Windows domain controllers (DCs).
The known issue impacts printers, scanners, and multifunction devices non-compliant with CVE-2021-33764 hardening changes and using smart card (PIV) authentication.
"The affected devices are smart card authenticating printers, scanners, and multifunction devices that don't support either Diffie-Hellman (DH) for key-exchange during PKINIT Kerberos authentication or don't advertise support for des-ede3-cbc ('triple DES') during the Kerberos AS request," Microsoft explained.
Luckily, according to Microsoft, all affected smart card authenticating devices will work as expected and won't be impacted if using username/ password authentication.
Temporary mitigation disabled across affected Windows Server versions
On Thursday, Microsoft said that the temporary fix has now been disabled by this week's optional preview updates on Windows Server 2019 systems. This change will lead to printing and scanning failures in Windows environments with non-compliant devices.
"Starting on July 21, 2022, this temporary mitigation will not be usable in security updates. The Windows July 2022 preview update will remove the temporary mitigation and will require compliant printing and scanning devices," the company said in a Windows message center update.
The temporary mitigation will also get removed on all affected Windows Server versions (Windows Server 2019, 2016, 2012, and 2008) by next month's Patch Tuesday security updates that will be released on August 9, 2022.
"All updates released on this day or later will be unable to use the temporary mitigation," Microsoft explains in an updated support document.
"Smartcard-authenticating printers and scanners must be compliant with section 3.2.1 of the RFC 4556 specification required for CVE-2021-33764 after installing these updates or later on Active Directory domain controllers."
To find non-compliant devices that will fail authentication after installing July 2022 or later updates on Windows DCs, admins should check logs on their Active Directory DCs for audit events identifying RFC-4456 incompatible printers added after deploying February 2022 Windows Server updates.
Comments
Shplad - 2 years ago
Jeez-us. AGAIN? What is this...the fifth time they've screwed this up? You'd think MS would want to maintain its market share, but apparently they couldn't care less.
h_b_s - 2 years ago
Arguably not Microsoft's problem this time. They gave corpos an entire year to update or replace standards non-compliant printers. If multi-million or multi-billion dollar corporations want to drag their feet, they can feel the pain with no sympathy from anyone that actually read the brief.
Bonzadog - 2 years ago
deleted
Bonzadog - 2 years ago
"Arguably not Microsoft's problem this time. They gave corpos an entire year to update or replace standards non-compliant printers. If multi-million or multi-billion dollar corporations want to drag their feet, they can feel the pain with no sympathy from anyone that actually read the brief."
So you find Microsoft forcing their standards on the manufactures
as being acceptable?
GeroldM - 2 years ago
Seriously? Replacing security hardware can be a lot more difficult than you think. Or way more costly. Or even worse, both.
Especially with security doors that come with reader panels built-in. Security is not only a reader attached to an USB port on your computer, but many secure locations have tamper proof readers. Not easy or cheap to replace those either.
Especially not at the whim of a software company, which didn't properly test their update. There is literally only cost and barely benefit involved for those companies. Microsoft may get away with their telemetry shenanigans reporting problems on normal users, companies that need and have invested serious money into security will not look so favorable against untested enterprise software.
Bonzadog - 2 years ago
"Jeez-us. AGAIN? What is this...the fifth time they've screwed this up? You'd think MS would want to maintain its market share, but apparently they couldn't care less."
Agreed, but I am now thinking of dumping MS and moving to Linux..