Windows Server 2022 VMs hosted on Hyper-V fails to decrypt Encrypted SMB messages as client

%3CLINGO-SUB%20id%3D%22lingo-sub-3055063%22%20slang%3D%22en-US%22%3EWindows%20Server%202022%20VMs%20hosted%20on%20Hyper-V%20fails%20to%20decrypt%20Encrypted%20SMB%20messages%20as%20client%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3055063%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EBackground%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EI%20recently%20tried%20to%20install%20SQL%20Server%20on%20a%20WS2022%20VM%20hosted%20on%20a%20WS2022%20Hyper-V%20host%2C%20but%20the%20installation%20failed%20with%20some%20cryptic%20error%20messages.%20After%202%20hours%20of%20searching%20online%20I%20finally%20realized%20that%20the%20installation%20media%20was%20corrupted%20while%20being%20copied%20from%20a%20SMB%20share%2C%20which%20is%20also%20hosted%20on%20WS2022.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EProblem%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EThen%20I%20tried%20to%20compute%20the%20hash%20of%20the%20installation%20media%20file%20over%20SMB%20with%20PowerShell%2C%20and%20astonishingly%20I%20got%20a%20different%20SHA-256%20hash%20each%20time%20I%20tried%20(of%20course%20unless%20when%20the%20file%20is%20still%20cached%20in%20memory).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Running%20Get-FileHash%20command%20on%20files%20over%20encrypted%20SMB%20shares%20gives%20a%20different%20hash%20each%20time%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F338131i610BDB5A54BB4B4C%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Image%201-3-22%20at%203.34%20AM.JPG%22%20alt%3D%22Running%20Get-FileHash%20command%20on%20files%20over%20encrypted%20SMB%20shares%20gives%20a%20different%20hash%20each%20time%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ERunning%20Get-FileHash%20command%20on%20files%20over%20encrypted%20SMB%20shares%20gives%20a%20different%20hash%20each%20time%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20through%20the%20SMBClient%20logs%20with%20Event%20Viewer%2C%20I%20could%20see%20a%20lot%20of%20events%20with%20ID%2031015%20indicating%20message%20decryption%20failed%20due%20to%20%22Bad%20data%22%2C%20and%20then%20the%20connection%20was%20immediately%20closed%20with%20event%20ID%2030804%20(which%20is%20to%20be%20expected%20when%20decryption%20fails%20according%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fopenspecs%2Fwindows_protocols%2Fms-smb2%2Fd3c03e33-7dc7-4d58-8428-0a1484c5c874%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMS-SMB2%20specification%203.2.5.1.1.1%3C%2FA%3E).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22SMBClient%20event%20logs%20showing%20a%20series%20of%20events%20with%20ID%2031015%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F338132iAB111C9F67F16640%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screen%20Shot%202022-01-08%20at%2011.53.04%20PM.png%22%20alt%3D%22SMBClient%20event%20logs%20showing%20a%20series%20of%20events%20with%20ID%2031015%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESMBClient%20event%20logs%20showing%20a%20series%20of%20events%20with%20ID%2031015%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20disabling%20SMB%20encryption%2C%20the%20problem%20went%20away%2C%20and%20I%20was%20able%20to%20copy%20files%20from%20SMB%20shares%20without%20any%20corruption.%20Re-enable%20encryption%2C%20and%20the%20problem%20resurfaces.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ETroubleshooting%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EI%20reproduced%20the%20problem%20with%20Wireshark%20attached%20to%20both%20the%20server%20and%20the%20client%20and%20saved%20the%20traces.%20However%2C%20the%20problem%20requires%20a%20large%20file%20transmission%20to%20surface%2C%20and%20I%20don't%20really%20have%20the%20time%20and%20patience%20to%20examine%20each%20TCP%20packet%20for%20corruption%20in%20transport.%20So%20instead%2C%20I%20conducted%20a%20series%20of%20tests%20trying%20to%20pinpoint%20the%20issue%2C%20and%20it%20seems%20to%20me%20that%20the%20problem%20is%20related%20to%20the%20guest%20virtual%20networking%20stack.%20I%20can't%20be%20100%25%20sure%20though.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Test%20results%20suggest%20that%20the%20problem%20on%20surfaces%20when%20the%20guest%20is%20hosted%20on%20Hyper-V%2C%20running%20WS2022%2C%20and%20is%20connected%20with%20a%20virtual%20switch%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F338133i4137EB4BB5CE0FCC%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screen%20Shot%202022-01-08%20at%2010.33.39%20PM.png%22%20alt%3D%22Test%20results%20suggest%20that%20the%20problem%20on%20surfaces%20when%20the%20guest%20is%20hosted%20on%20Hyper-V%2C%20running%20WS2022%2C%20and%20is%20connected%20with%20a%20virtual%20switch%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ETest%20results%20suggest%20that%20the%20problem%20on%20surfaces%20when%20the%20guest%20is%20hosted%20on%20Hyper-V%2C%20running%20WS2022%2C%20and%20is%20connected%20with%20a%20virtual%20switch%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EEnvironment%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EIn%20the%20tests%20above%2C%20all%20Windows%20Server%20VM%20instances%20are%20freshly%20installed%20with%20the%20latest%20cumulative%20updates%20applied.%20All%20hardware%20acceleration%20features%20on%20the%20virtual%20network%20adapters%20are%20disabled%20except%20for%20SR-IOV%20when%20indicated.%20Virtual%20TPM%20and%20migration%20traffic%20encryption%20are%20both%20enabled.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20physical%20Hyper-V%20host%20running%20WS2022%20is%20a%20Dell%20PowerEdge%20R750%20with%20a%20pair%20of%20Intel%20Xeon%204316%20CPUs%20and%20a%204-port%20Intel%20X710%2010GbE%20NIC%20capable%20of%20SR-IOV%20%3CEM%3E%3CFONT%20color%3D%22%23999999%22%3E(which%20by%20the%20way%20has%20a%20buggy%20driver%20which%20often%20bugchecks%20the%20host%20when%20I%20change%20the%20SR-IOV%20setting%20on%20vEthernet%20adapters%2C%20but%20that's%20another%20story)%3C%2FFONT%3E%3C%2FEM%3E.%20TPM%20and%20Intel%20TME%20are%20both%20enabled.%20It%20has%20the%20latest%20firmware%2C%20driver%2C%20and%20OS%20cumulative%20updates%20installed%2C%20and%20a%20system%20file%20check%20with%20SFC%20reported%20no%20integrity%20violations.%20I%20also%20ran%20the%20hardware%20diagnostic%20utility%20provided%20by%20Dell%2C%20which%20reported%20no%20hardware%20issues.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestion%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3ENow%20I%20am%20working%20around%20the%20issue%20by%20sticking%20to%20SR-IOV%20for%20all%20my%20WS2022%20VMs.%20However%2C%20that%20also%20means%20that%20I%20can%20only%20use%20external%20switches%2C%20and%20features%20like%20NIC%20teaming%20cannot%20work.%20Therefore%2C%20I%20would%20like%20to%20understand%20the%20reason%20and%20to%20see%20if%20there's%20a%20more%20permanent%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20a%20lot%20in%20advance%2C%20and%20feel%20free%20to%20ask%20if%20more%20information%20or%20troubleshooting%20is%20needed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3055063%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHyper-V%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EStorage%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

Background

I recently tried to install SQL Server on a WS2022 VM hosted on a WS2022 Hyper-V host, but the installation failed with some cryptic error messages. After 2 hours of searching online I finally realized that the installation media was corrupted while being copied from a SMB share, which is also hosted on WS2022.

 

Problem

Then I tried to compute the hash of the installation media file over SMB with PowerShell, and astonishingly I got a different SHA-256 hash each time I tried (of course unless when the file is still cached in memory).

 

Running Get-FileHash command on files over encrypted SMB shares gives a different hash each timeRunning Get-FileHash command on files over encrypted SMB shares gives a different hash each time

 

Looking through the SMBClient logs with Event Viewer, I could see a lot of events with ID 31015 indicating message decryption failed due to "Bad data", and then the connection was immediately closed with event ID 30804 (which is to be expected when decryption fails according to the MS-SMB2 specification 3.2.5.1.1.1).

 

SMBClient event logs showing a series of events with ID 31015SMBClient event logs showing a series of events with ID 31015

 

After disabling SMB encryption, the problem went away, and I was able to copy files from SMB shares without any corruption. Re-enable encryption, and the problem resurfaces.

 

Troubleshooting

I reproduced the problem with Wireshark attached to both the server and the client and saved the traces. However, the problem requires a large file transmission to surface, and I don't really have the time and patience to examine each TCP packet for corruption in transport. So instead, I conducted a series of tests trying to pinpoint the issue, and it seems to me that the problem is related to the guest virtual networking stack. I can't be 100% sure though.

 

UNRELIABLE: Test results suggest that the problem on surfaces when the guest is hosted on Hyper-V, running WS2022, and is connected with a virtual switchUNRELIABLE: Test results suggest that the problem on surfaces when the guest is hosted on Hyper-V, running WS2022, and is connected with a virtual switch

 

UPDATE (1/9/2022 15:50 UTC):

Just discovered that decryption fails even when SR-IOV is enabled. Maybe my tests weren't so reliable after all.

 

I turned on checksum validation in Wireshark and saw a huge amount of checksum validation errors on both client side and server side. In fact, nearly all packets had bad checksums. Wireshark suggested that this behavior could be cause by checksum offloading, so I retried after disabling checksum offloading on both the server and the client VMs with Disable-NetAdapterChecksumOffload cmdlet. Unfortunately the problem persisted. Note that this test was performed with a private virtual switch, so external networking infrastructure should have nothing to do with the problem here.

 

Client-side Wireshark trace showing excessive TCP checksum validation failuresClient-side Wireshark trace showing excessive TCP checksum validation failures

 

Environment

In the tests above, all Windows Server VM instances are freshly installed with the latest cumulative updates applied. All hardware acceleration features on the virtual network adapters are disabled except for SR-IOV when indicated. Virtual TPM and migration traffic encryption are both enabled.

 

The physical Hyper-V host running WS2022 is a Dell PowerEdge R750 with a pair of Intel Xeon 4316 CPUs and a 4-port Intel X710 10GbE NIC capable of SR-IOV (which by the way has a buggy driver which often bugchecks the host when I change the SR-IOV setting on vEthernet adapters, but that's another story). TPM and Intel TME are both enabled. It has the latest firmware, driver, and OS cumulative updates installed, and a system file check with SFC reported no integrity violations. I also ran the hardware diagnostic utility provided by Dell, which reported no hardware issues.

 

Question

Now I am working around the issue by not using SMB encryption. However, that also means I lose the associated security benefits. Therefore, I would like to understand the reason and to see if there's a more permanent solution.

 

Thanks a lot in advance, and feel free to ask if more information or troubleshooting is needed.

 

0 Replies