diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index abaa9848..61b868f1 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -14,7 +14,7 @@ **バグ修正:** -- 通常の`configure`と`configure -Profile`で、詳細監査サブカテゴリを適用する前に`SCENoApplyLegacyAuditPolicy=1` (DWORD)の変更前の状態を記録し、設定後の値を検証するようにした。前提設定の変更に失敗した場合や変更を拒否した場合は、依存する書き込みを行わない。書き込み直前と最終確認で設定の変化を検出し、プロファイルの計画には現在の状態と取得可能な最終適用RSoP情報を含める。ポリシー更新後の永続性は保証しない。 (issue #374) (@Shirofune-Security) +- 通常の`configure`と`configure -Profile`で、詳細監査サブカテゴリを適用する前に`SCENoApplyLegacyAuditPolicy=1` (DWORD)の変更前の状態を記録し、設定後の値を検証するようにした。前提設定の変更に失敗した場合や変更を拒否した場合は、依存する書き込みを行わない。書き込み直前と最終確認で設定の変化を検出し、プロファイルの計画には現在の状態と取得可能な最終適用RSoP情報を含める。ポリシー更新後の永続性は保証しない。 (#393) (@Shirofune-Security) - `configure`が既定で送信NTLM認証をブロックしていた問題を修正した。未設定またはAllow allの場合はAudit all (`RestrictSendingNTLMTraffic=1`)を設定し、既存のDeny all (`2`)や不明な値・型は維持する。拒否設定を明示的に監査へ変更するには`-OutgoingNtlmMode Audit`、ブロックを有効にするには`Deny`を指定する。書き込み前にポリシーを再確認し、変更後の値の検証、失敗の報告、確認できたポリシー状態と取得可能な最終適用RSoP情報の表示に対応した。 (#388) (@Shirofune-Security) - `audit-settings`でホストの役割に適用されない監査ポリシーを`Not applicable`と表示し、カテゴリの有効・無効の集計から除外するようにした。NTLMポリシーの値は、DWORD型で保存されている場合にのみ有効な設定値として解釈・検証する。 (#392) (@Shirofune-Security) - 設定時に外部コマンドの終了コードと変更後の設定値を確認し、処理の終了前にも再確認するようにした。書き込み失敗、設定の未反映、CAサービスの再起動失敗、最終確認時の設定の不一致を明示的に報告し、一律に成功とせず、0以外の終了コードを返すようにした。 (#392) (@Shirofune-Security) diff --git a/CHANGELOG.md b/CHANGELOG.md index cdeacb5b..4e15e621 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,7 +16,7 @@ **Bug Fixes:** -- Both `configure` paths now journal and verify `SCENoApplyLegacyAuditPolicy=1` (DWORD) before applying advanced audit subcategories. Failed or declined precedence changes block dependent writes; pre-write and final checks detect drift. Profile plans report precedence state and available last-applied RSoP evidence without claiming persistence through policy refresh. (issue #374) (@Shirofune-Security) +- Both `configure` paths now journal and verify `SCENoApplyLegacyAuditPolicy=1` (DWORD) before applying advanced audit subcategories. Failed or declined precedence changes block dependent writes; pre-write and final checks detect drift. Profile plans report precedence state and available last-applied RSoP evidence without claiming persistence through policy refresh. (#393) (@Shirofune-Security) - Fixed `configure` enabling outgoing NTLM blocking by default. It now sets Audit all (`RestrictSendingNTLMTraffic=1`) for unset or Allow policies while preserving existing Deny all (`2`) and unknown values/types. Use `-OutgoingNtlmMode Audit` to explicitly replace a deny policy, or `Deny` to enable blocking. Configuration rechecks policy before writing, verifies changes, reports failures, and displays the observed policy and available last-applied RSoP information. (#388) (@Shirofune-Security) - `audit-settings` now reports role-inapplicable audit policies as `Not applicable` and excludes them from category enablement totals. NTLM policy values are interpreted and verified only when stored as DWORDs. (#392) (@Shirofune-Security) - Configuration now checks native command exit codes, verifies settings after applying changes, and checks them again before finishing. Failed writes, ineffective changes, CA restart failures and settings that no longer match at the final check produce explicit results and a nonzero exit code instead of unconditional success. (#392) (@Shirofune-Security) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 02dbed6f..5fd23506 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -17,7 +17,7 @@ **バグ修正:** -- 通常の`configure`と`configure -Profile`で、詳細監査サブカテゴリを適用する前に`SCENoApplyLegacyAuditPolicy=1` (DWORD)の変更前の状態を記録し、設定後の値を検証するようにした。前提設定の変更に失敗した場合や変更を拒否した場合は、依存する書き込みを行わない。書き込み直前と最終確認で設定の変化を検出し、プロファイルの計画には現在の状態と取得可能な最終適用RSoP情報を含める。ポリシー更新後の永続性は保証しない。 (issue #374) (@Shirofune-Security) +- 通常の`configure`と`configure -Profile`で、詳細監査サブカテゴリを適用する前に`SCENoApplyLegacyAuditPolicy=1` (DWORD)の変更前の状態を記録し、設定後の値を検証するようにした。前提設定の変更に失敗した場合や変更を拒否した場合は、依存する書き込みを行わない。書き込み直前と最終確認で設定の変化を検出し、プロファイルの計画には現在の状態と取得可能な最終適用RSoP情報を含める。ポリシー更新後の永続性は保証しない。 (#393) (@Shirofune-Security) - `configure`が既定で送信NTLM認証をブロックしていた問題を修正した。未設定またはAllow allの場合はAudit all (`RestrictSendingNTLMTraffic=1`)を設定し、既存のDeny all (`2`)や不明な値・型は維持する。拒否設定を明示的に監査へ変更するには`-OutgoingNtlmMode Audit`、ブロックを有効にするには`Deny`を指定する。書き込み前にポリシーを再確認し、変更後の値の検証、失敗の報告、確認できたポリシー状態と取得可能な最終適用RSoP情報の表示に対応した。 (#388) (@Shirofune-Security) - `audit-settings`でホストの役割に適用されない監査ポリシーを`Not applicable`と表示し、カテゴリの有効・無効の集計から除外するようにした。NTLMポリシーの値は、DWORD型で保存されている場合にのみ有効な設定値として解釈・検証する。 (#392) (@Shirofune-Security) - 設定時に外部コマンドの終了コードと変更後の設定値を確認し、処理の終了前にも再確認するようにした。書き込み失敗、設定の未反映、CAサービスの再起動失敗、最終確認時の設定の不一致を明示的に報告し、一律に成功とせず、0以外の終了コードを返すようにした。 (#392) (@Shirofune-Security) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 7a75424d..aa8c6763 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -19,7 +19,7 @@ **Bug Fixes:** -- Both `configure` paths now journal and verify `SCENoApplyLegacyAuditPolicy=1` (DWORD) before applying advanced audit subcategories. Failed or declined precedence changes block dependent writes; pre-write and final checks detect drift. Profile plans report precedence state and available last-applied RSoP evidence without claiming persistence through policy refresh. (issue #374) (@Shirofune-Security) +- Both `configure` paths now journal and verify `SCENoApplyLegacyAuditPolicy=1` (DWORD) before applying advanced audit subcategories. Failed or declined precedence changes block dependent writes; pre-write and final checks detect drift. Profile plans report precedence state and available last-applied RSoP evidence without claiming persistence through policy refresh. (#393) (@Shirofune-Security) - Fixed `configure` enabling outgoing NTLM blocking by default. It now sets Audit all (`RestrictSendingNTLMTraffic=1`) for unset or Allow policies while preserving existing Deny all (`2`) and unknown values/types. Use `-OutgoingNtlmMode Audit` to explicitly replace a deny policy, or `Deny` to enable blocking. Configuration rechecks policy before writing, verifies changes, reports failures, and displays the observed policy and available last-applied RSoP information. (#388) (@Shirofune-Security) - `audit-settings` now reports role-inapplicable audit policies as `Not applicable` and excludes them from category enablement totals. NTLM policy values are interpreted and verified only when stored as DWORDs. (#392) (@Shirofune-Security) - Configuration now checks native command exit codes, verifies settings after applying changes, and checks them again before finishing. Failed writes, ineffective changes, CA restart failures and settings that no longer match at the final check produce explicit results and a nonzero exit code instead of unconditional success. (#392) (@Shirofune-Security)