Forum Discussion

Arek Kozuch's avatar
Arek Kozuch
Copper Contributor
Aug 05, 2020

Logging SChannel to include remote endpoint name

Hi, 

 

question regarding Windows Server SChannel Behaviour. When we are getting any SChannel error messages, we are not able to trace, what is actually trying to connect and causing the error. Is there any way to include in SChannel errors information regarding endpoint failing to negotiate the TLS connection?

 

Thanks in advance,

Arek

1 Reply

  • MiguelSalinas's avatar
    MiguelSalinas
    Copper Contributor

    Arek Kozuch 

     

    Hi!!

     

    If the issue cannot be solved, or the error is expected, there is always the option of turning off Schannel logging altogether by setting EventLogging=0 (dword), under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL. Hiding the log is not good security practice, but it is an option.

     

    Regards,

     

Resources