Windows 7 SMB

Got windows 7 installed and found an interesting setting.  NTML version 2 is set by default and doesnt negotiate with v1 servers.  Connecting to a mac os share would state access denied regardless of the credentials.  The trick is to enable v1 if v2 doesn’t negotiate.

Open up the local security policy by running secpol.msc

Navigate to Local Policies -> Security Policies

Change Network Security: LAN Manager authentication level to: Send LM & NTLM - Use NTLMv2 session security if negotiated.

Close security policy and reconnect to the share.  If it still doesnt work change the encryption level to not require 128 bit encryption.

Open Network security: Minimum session security for NTLM SSP based (including secure RPC) clients and uncheck the require 128 bit.

Open Network security: Minimum session security for NTLM SSP based (including secure RPC) servers and uncheck the require 128 bit.

Reconnect to the share and it should connect correctly.

6 Comments

  1. Posted March 3, 2009 at 8:40 pm | Permalink

    Thank you so much for this, I searched fairly hard and couldn’t find out why I couldn’t access my mac shares, I previously knew about “Send LM & NTLM - Use NTLMv2 session security if negotiated” but not about the 128bit encryption options.

  2. eric stassen
    Posted December 29, 2009 at 11:49 am | Permalink

    Good afternoon … thanks so much. You found the answer. XP always worked like a dream but Vista and 7 struggled logging onto the Mac servers. This is very helpful!! Happy New Year!!

  3. Christian
    Posted February 4, 2010 at 2:46 pm | Permalink

    Thanks man :)

  4. Colin Ashdown
    Posted February 10, 2010 at 10:39 am | Permalink

    Please can someone tell me what registry changes I need to make to resolve this problem on Windows 7 Premium which doesn’t have secpol.msc?
    Thank you

  5. Posted February 25, 2010 at 12:08 pm | Permalink

    Very Helpful! This saved my butt today!

  6. Posted March 16, 2010 at 8:53 am | Permalink

    Great info
    I solved a companywide problem because of this

2 Trackbacks

  1. [...] procedure on Win 7, due to access control protocols, that would seem to apply to both situations: http://www.mostlyoperational.com/?p=86 This is one bit that Microsoft has to say about it: [...]

  2. By Windows 7 SMB | Mostly Operational on June 20, 2010 at 8:17 am

    [...] If you are looking for my windows 7 smb post you can find it here: http://www.mostlyoperational.com/archive/?p=86 [...]

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*