Overview

On Monday, March 15, 2027, ITS will begin requiring encryption for all connections to SMB network shares hosted by the Files@Iowa (UDSS departmental and application shares, Home drives) and Research Data Storage Service (RDSS) services.  Encrypting this storage traffic over the network improves security.

The SMB 3 protocol version is required to support encrypted sessions, but older clients may not support SMB 3.

This article provides guidance to help identify possible compatibility issues and advice on addressing those issues.  Where possible, ITS support staff will also be reaching out to users identified as connecting from devices using older SMB versions.

Scope

The services in scope for the new encryption requirement include:

Services not in scope include:

  • NFS shares on Files@Iowa (UDSS) or RDSS
  • Files@Iowa ADSS shares (already require encryption)
  • Large Scale Storage (LSS)
  • R: Drive
  • OneDrive

Compatibility

Computers

Any client that supports SMB 3 should have no issues using encrypted SMB connections.  That includes all versions of Microsoft Windows (desktop and server), Apple macOS, and Linux distributions that are currently supported by their respective vendors.  However, there are some older computers and devices on campus that will not support SMB encryption which will require attention before the March 15 change.

General guidance on support for SMB 3 and encryption:

Operating SystemSMB 3 SupportedSMB 3 Not Supported
Windows DesktopWindows 8 or newerWindows 7 or older
Windows ServerServer 2012 or newerServer 2008 R2 or older
macOSOS X 10.10 (Yosemite) or newerOS X 10.9 (Mavericks) or older
RHEL/CentOS Linux7.x or newer6.x or older
Ubuntu Linux14.04 or newer12.04 or older
Other LinuxSamba 4.x or newerSamba 3.x or older
  • Note that for macOS and Linux, the transition versions could depend on specific package versions or vendor customization, so SMB 3 support is expected but not guaranteed.

Other Devices

Non-computer devices, such as multi-function printers/scanners and other devices with embedded network share capabilities (e.g. laboratory or medical devices not using an external control PC), may not support SMB 3 connections.  This category of devices is wide-ranging, so specific devices are not identified here.

Generally, the older the device, the less likely it is to support SMB 3.  To identify device capabilities, refer to vendor documentation, support contacts, or lease vendors, as appropriate.

Testing

To aid in determining whether your computer or device supports encrypted SMB sessions, you can connect to the following SMB share:

\\itfna1test.iowa.uiowa.edu\smb3

All authenticated IOWA domain users have read access to that share.  If you can connect successfully to the share (you will see a folder named "Successful Encrypted SMB3 Connection"), that client is able to use encrypted SMB sessions.

If you cannot connect to that share, review the Advice section below and work with your local IT support staff.

Advice

There are a few options if your device does not support SMB encryption but it still requires access to an SMB share in scope.

  • The recommended option (where possible) is to upgrade or replace that device with a newer one that does support SMB 3.
    • Devices too old for SMB 3 are likely out of compliance with the University Policy Manual and IT Security policies.
    • For devices on lease (e.g. some MFPs), contact the lease vendor for options.
  • For computers accessing shares with DFS links, those shares can be accessed through the SFTP/FTPS service.  Note that Home Drive shares are not accessible this way, nor are some UDSS and RDSS shares; try accessing the share via that DFS path to verify, typically:
    • UDSS:  \\iowa.uiowa.edu\Shared\[sharename]
    • RDSS:  \\iowa.uiowa.edu\Shared\ResearchData\[sharename]
  • Use another intermediate system for data transfer.  Specifics of this option will vary greatly depending on the device/situation in question.

Note:  No per-share security exceptions are possible.  The settings to require encryption are service-wide.

 

Last updated
Article number
13576