新年あけましておめでとうございました。
(※以下は、AD DS または AD LDS 運用中の管理者向けに注意しておいたほうがいい”かもしれない”話。AD DS/AD LDS を使っていないところや個人の Windows ユーザーには無関係な話。)
以下の公式ブログにあるように、2020年3月のWindows Updateで、Active Directory (AD DS および AD LDS)に関連する重要な変更(既定のセキュリティ設定の強化)が予定されているそうです。2020年3月は2019年12月時点での予定。
[AD管理者向け] 2020 年 LDAP 署名と LDAP チャネルバインディングが有効化。確認を!(Microsoft Security Response Center)
https://msrc-blog.microsoft.com/2019/10/02/ldapbinding/
2/6 追記) こちらも更新されました "注釈1:2020 年 2 月 5 日時点では、2020 年後半を予定しています。"
上記のブログにあるように、AD 運用している場合は事前にテストしておいたほうが良いと思います。2019年8月のセキュリティアドバイザリ ADV190023(
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/adv190023) で周知してきたと書いてますが、知らない AD 管理者は多いのでは? 事前にテストしておかないと、3 月の Windows Update の後に大変なことになるかもしれないし、ならないかもしれない。
2/5 追記)2/4 PT 付で ADV190023 が更新されました。2020 年後半に延期だそうです。
"The March 2020 updates do not make changes to LDAP signing or channel
binding policies or their registry equivalent on new or existing domain
controllers.
A further future monthly update, anticipated for release the
second half of calendar year 2020, will enable LDAP signing and channel
binding on domain controllers configured with default values for those
settings."
3/3 追記) AD LDS は影響なしになったらしい。
2021/1/5 追記)さらに更新。"The March 10, 2020 and updates in the foreseeable future will not make changes to LDAP signing or LDAP channel binding policies or their registry equivalent on new or existing domain controllers." (2020年後半というのものも消え、当面既定を変更することはないみたい)