Skip to content

Commit

Permalink
Merge pull request #51 from cnotin/patch-1
Browse files Browse the repository at this point in the history
Add potential false-positive notice to "A_NoServicePolicy"
  • Loading branch information
vletoux committed Aug 1, 2020
2 parents 4d0e747 + 2942800 commit 80fb439
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion Healthcheck/Rules/RuleDescription.resx
Original file line number Diff line number Diff line change
Expand Up @@ -452,7 +452,8 @@ To change it you can edit the owner of an object using <a href="https://docs.
<value>GPO: {0} Subject: {1}</value>
</data>
<data name="A_NoServicePolicy_Description" xml:space="preserve">
<value>The purpose is to give information regarding a best practice for the Service Account password policy. Indeed, having a 20+ characters password for this account greatly helps reducing the risk behind Kerberoast attack (offline crack of the TGS tickets)</value>
<value>The purpose is to give information regarding a best practice for the Service Account password policy. Indeed, having a 20+ characters password for this account greatly helps reducing the risk behind Kerberoast attack (offline crack of the TGS tickets)
Note: PSO (Password Settings Objects) will be visible only if the user which collected the information has the permission to view it.</value>
</data>
<data name="A_NoServicePolicy_Solution" xml:space="preserve">
<value> The recommended way to handle service accounts is to use "Managed service accounts" introduced since Windows 2008 R2 (search for "msDS-ManagedServiceAccount").
Expand Down

0 comments on commit 80fb439

Please sign in to comment.