Forum Discussion

Wes808's avatar
Wes808
Brass Contributor
Oct 20, 2024

SMB over QUIC Client Access Control is inconsistent

We have set up SMB over QUIC on some Windows 2025 file servers and generally it works well.  Unfortunately of course, it is not secure by design since there is no MFA or conditional access in the pic...
  • Wes808's avatar
    Wes808
    Nov 13, 2024

    In our case the issue was the certificate EKU.  Almost 100% sure the guidance was followed when we set this up many months ago, so I believe the doc has since been updated - regardless it does clearly point out that Client Authentiation needs to be an EKU:

    https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-over-quic-client-access-control

    Once we reissued a cert with Client Auth in the EKU, CAC started working for us.  w00t!

Resources