Dell EMC Unity:SMB error: Access Denied when accessing Protocol Encrypted Share. (User Correctable)

Summary: Impact : Unity SMB Shares will disallow Legacy SMB clients (as Windows7) access if Protocol Encryption is turned on.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms



Customer is trying to access a CIFS Share and is receiving : ACCESS DENIED, Re authentication window requested:
 
kA2j0000000REI1CAO_3_0

Cause



 Protocol Encryption is turned on this Share - prohibits access from SMB2/1 Legacy Protocols.

   kA2j0000000REI1CAO_1_0

Resolution



  Protocol Encryption is Supported in SMB3 type clients only. That means only Windows 8/10 or 2012 server supports it.
  If any legacy Windows exist , however , we may still have the option to allow access using remote registry tool.
  open regedit  as domain admin account and remote connect to the unity CIFS server , change the following value to 0 :
  
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters


     kA2j0000000REI1CAO_2_0

 Once changed to zero , effect takes place on the fly and the share becomes available to legacy clients.

 

Additional Information



 Microsoft similar code behavior is described here:
  
  https://technet.microsoft.com/en-us/library/dn551363(v=ws.11).aspx

From the article :

 The secure dialect negotiation capability described in the next section prevents a man-in-the-middle attack from downgrading a connection from SMB 3.0 to SMB 2.0 (which would use unencrypted access). However, it does not prevent a downgrade to SMB 1.0, which would also result in unencrypted access. To guarantee that SMB 3.0 clients always use SMB Encryption to access encrypted shares, you must disable the SMB 1.0 server. (For instructions, see the section Disabling SMB 1.0.) If the  RejectUnencryptedAccess setting is left at its default setting of $true, only encryption-capable SMB 3.0 clients are allowed to access the file shares (SMB 1.0 clients will also be rejected).


Affected Products

Dell EMC Unity Family

Products

Dell EMC Unity Family
Article Properties
Article Number: 000054814
Article Type: Solution
Last Modified: 30 May 2024
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.