You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows 10自定义PasswordFilter无法配置问题求助

Troubleshooting Your Custom PasswordFilter.dll on Windows 10

Let's walk through the missing configuration steps and critical code issues that are preventing your filter from working properly:

First: Fix the Configuration Gaps on Windows 10

Even if you've added the DLL to LSA->NotificationPackage and copied it to C:\Windows\System32, there are a few Windows 10-specific requirements you might have missed:

  • Restart your system after registry changes
    The LSA service only loads password filter DLLs during system startup. A simple registry edit won't trigger a reload—you must reboot for changes to take effect.

  • Verify the Registry Entry Format
    Navigate to HKLM\SYSTEM\CurrentControlSet\Control\Lsa and check the NotificationPackage multi-string value:

    • Your DLL name should be listed without the .dll suffix (e.g., PasswordFilter, not PasswordFilter.dll).
    • Ensure each entry is on a separate line (don't concatenate multiple DLL names in one line).
    • Avoid placing your DLL at the top of the list—LSA processes filters in order, so placing it last avoids conflicts with built-in filters.
  • Check Permissions for the DLL and Log Path

    • The DLL in C:\Windows\System32 must have Read & Execute permissions for the SYSTEM account (this is usually default, but double-check if you copied it manually).
    • The log path c:\AmitPasswordFilter.log might trigger write permissions issues. By default, the SYSTEM account can write to C:\ but some security policies block this. Switch to C:\Windows\Temp\AmitPasswordFilter.log instead—this directory is guaranteed to have write access for SYSTEM.
  • Handle Windows 10's Signature Requirement
    Starting with Windows 10 1607, LSA will only load digitally signed password filter DLLs. For development/testing:

    1. Enable test signing mode via an elevated command prompt:
      bcdedit /set testsigning on
      
    2. Reboot your system.
    3. Sign your DLL with a test certificate (use signtool.exe from the Windows SDK).
      For production, you'll need a certificate from a trusted CA (or your enterprise CA).

Second: Fix Critical Issues in Your Code

Your code has several bugs that are preventing logging and proper filter functionality:

1. Invalid Log File Path (Biggest Culprit!)

In InitializeChangeNotify, your path uses a single backslash:

wchar_t *pLogFile = L"c:\AmitPasswordFilter.log";

C++ interprets \A as an escape sequence, so the actual path becomes invalid. You need to escape backslashes:

wchar_t *pLogFile = L"c:\\Windows\\Temp\\AmitPasswordFilter.log";

2. Unchecked File Open Operation

You don't verify if the log file opened successfully. Add a check to avoid writing to an invalid stream:

writeLog.open(aLogFileExp, ios::out|ios::app);
if (!writeLog.is_open()) {
    // Optionally log to event viewer here, but at least return TRUE to avoid blocking LSA
    return TRUE;
}

3. Broken Loop Logic in PasswordFilter

Your nested for loops have duplicate variable names (i) and incorrect structure:

  • The outer for(int i=0;i<cathegories;i++) is unnecessary and causes your regex to be built multiple times.
  • You return match; inside the outer loop, so the function exits on the first iteration.

Here's the fixed regex construction section:

std::wstring regExp(L"(?=");
const int categories = 4;
unsigned int aRegCondition[categories] = {2, 2, 2, 2};

// Add digit requirement
for(int i=0;i<aRegCondition[0];i++)
    regExp += L".*\\d";
regExp += L")(?=";

// Add special character requirement
for(int i=0;i<aRegCondition[1];i++)
    regExp += L".*\\W";
regExp += L")(?=";

// Add uppercase requirement
for(int i=0;i<aRegCondition[2];i++)
    regExp += L".*[A-Z]";
regExp += L")(?=";

// Add lowercase requirement
for(int i=0;i<aRegCondition[3];i++)
    regExp += L".*[a-z]";
regExp += L")(?![.\\n]).*$";

4. Outdated std::tr1 Usage

Modern compilers integrate regex into the standard std namespace. Remove using namespace std::tr1; and use std::wregex/std::regex_search directly.


Testing the Fixes

After applying these changes:

  1. Recompile your DLL with the fixes.
  2. Sign it (if in test mode) and copy to C:\Windows\System32.
  3. Double-check the registry entry.
  4. Reboot your system.
  5. Try changing a local user's password.
  6. Check the log file in C:\Windows\Temp—it should now have entries from InitializeChangeNotify and PasswordFilter.

If you still don't see logs, check the System Event Log (Event Viewer > Windows Logs > System) for events from the LSA source—these will tell you if the DLL failed to load (e.g., signature issues, missing dependencies).

内容的提问来源于stack exchange,提问作者Amit Jha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:23:16