Windows 10自定义PasswordFilter无法配置问题求助
Let's walk through the missing configuration steps and critical code issues that are preventing your filter from working properly:
First: Fix the Configuration Gaps on Windows 10
Even if you've added the DLL to LSA->NotificationPackage and copied it to C:\Windows\System32, there are a few Windows 10-specific requirements you might have missed:
Restart your system after registry changes
The LSA service only loads password filter DLLs during system startup. A simple registry edit won't trigger a reload—you must reboot for changes to take effect.Verify the Registry Entry Format
Navigate toHKLM\SYSTEM\CurrentControlSet\Control\Lsaand check theNotificationPackagemulti-string value:- Your DLL name should be listed without the
.dllsuffix (e.g.,PasswordFilter, notPasswordFilter.dll). - Ensure each entry is on a separate line (don't concatenate multiple DLL names in one line).
- Avoid placing your DLL at the top of the list—LSA processes filters in order, so placing it last avoids conflicts with built-in filters.
- Your DLL name should be listed without the
Check Permissions for the DLL and Log Path
- The DLL in
C:\Windows\System32must have Read & Execute permissions for the SYSTEM account (this is usually default, but double-check if you copied it manually). - The log path
c:\AmitPasswordFilter.logmight trigger write permissions issues. By default, the SYSTEM account can write toC:\but some security policies block this. Switch toC:\Windows\Temp\AmitPasswordFilter.loginstead—this directory is guaranteed to have write access for SYSTEM.
- The DLL in
Handle Windows 10's Signature Requirement
Starting with Windows 10 1607, LSA will only load digitally signed password filter DLLs. For development/testing:- Enable test signing mode via an elevated command prompt:
bcdedit /set testsigning on - Reboot your system.
- Sign your DLL with a test certificate (use
signtool.exefrom the Windows SDK).
For production, you'll need a certificate from a trusted CA (or your enterprise CA).
- Enable test signing mode via an elevated command prompt:
Second: Fix Critical Issues in Your Code
Your code has several bugs that are preventing logging and proper filter functionality:
1. Invalid Log File Path (Biggest Culprit!)
In InitializeChangeNotify, your path uses a single backslash:
wchar_t *pLogFile = L"c:\AmitPasswordFilter.log";
C++ interprets \A as an escape sequence, so the actual path becomes invalid. You need to escape backslashes:
wchar_t *pLogFile = L"c:\\Windows\\Temp\\AmitPasswordFilter.log";
2. Unchecked File Open Operation
You don't verify if the log file opened successfully. Add a check to avoid writing to an invalid stream:
writeLog.open(aLogFileExp, ios::out|ios::app); if (!writeLog.is_open()) { // Optionally log to event viewer here, but at least return TRUE to avoid blocking LSA return TRUE; }
3. Broken Loop Logic in PasswordFilter
Your nested for loops have duplicate variable names (i) and incorrect structure:
- The outer
for(int i=0;i<cathegories;i++)is unnecessary and causes your regex to be built multiple times. - You
return match;inside the outer loop, so the function exits on the first iteration.
Here's the fixed regex construction section:
std::wstring regExp(L"(?="); const int categories = 4; unsigned int aRegCondition[categories] = {2, 2, 2, 2}; // Add digit requirement for(int i=0;i<aRegCondition[0];i++) regExp += L".*\\d"; regExp += L")(?="; // Add special character requirement for(int i=0;i<aRegCondition[1];i++) regExp += L".*\\W"; regExp += L")(?="; // Add uppercase requirement for(int i=0;i<aRegCondition[2];i++) regExp += L".*[A-Z]"; regExp += L")(?="; // Add lowercase requirement for(int i=0;i<aRegCondition[3];i++) regExp += L".*[a-z]"; regExp += L")(?![.\\n]).*$";
4. Outdated std::tr1 Usage
Modern compilers integrate regex into the standard std namespace. Remove using namespace std::tr1; and use std::wregex/std::regex_search directly.
Testing the Fixes
After applying these changes:
- Recompile your DLL with the fixes.
- Sign it (if in test mode) and copy to
C:\Windows\System32. - Double-check the registry entry.
- Reboot your system.
- Try changing a local user's password.
- Check the log file in
C:\Windows\Temp—it should now have entries fromInitializeChangeNotifyandPasswordFilter.
If you still don't see logs, check the System Event Log (Event Viewer > Windows Logs > System) for events from the LSA source—these will tell you if the DLL failed to load (e.g., signature issues, missing dependencies).
内容的提问来源于stack exchange,提问作者Amit Jha

