Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

SescLU.exe resets permissions on HKEY_USERS\.Default\Software\Microsoft\SystemCertificates\Root\ProtectedRoots

Updated: 21 May 2010 | 5 comments
HCTRA's picture
0 0 Votes
Login to vote

We are trying to harden servers and workstations for PCI compliance. One of the steps is to tighten permissions on HKEY_USERS\.Default\Software\Microsoft\SystemCertificates\Root\ProtectedRoots. When we do this, within two minutes SescLU.exe reverts the permissions on the key.

Is there a way to stop this from happenning?

Comments

Jason1222's picture
06
Oct
2009
0 Votes 0
Login to vote

The only permissions you need

The only permissions you need on this key are READ for all users that will be using the system.
What permissions are you setting on this key and what is Symantec reverting it back to?

HCTRA's picture
06
Oct
2009
0 Votes 0
Login to vote

I am setting

I am setting BUILTIN\Administrators=Full Control, NT AUTHORITY\SYSTEM=Full Control, BUILTIN\Users=Read per our policy rules. As soon as I update content from the console or update policy from the client, it reverts it back to EVERYONE=Read and NT AUTHORITY\SYSTEM=Full Control.

HCTRA's picture
08
Oct
2009
0 Votes 0
Login to vote

Systems affected

It appears to be doing this on both Windows 2003 Server and XP.

Has anyone else dealing with PCI compliance experienced this behavior?

RAJP's picture
13
Oct
2009
0 Votes 0
Login to vote

What PCI requirement are you trying to comply with?

Since "everyone" is effectively "authenticated users" nowadays, is there really a difference?

I'm pretty conversant in PCI, or so I thought, and we've never had an issue like this pop up. Where is it coming from?

Ray