Spread the word.

Share the link on social media.

Share
  • Facebook
Have an account? Sign In Now

Sign Up

Create your WindowsTechno Community account. It’s free and only takes a minute.

Have an account? Sign In
Continue with Facebook
Continue with Google
or use

Have an account? Sign In Now

Sign In

Continue with Facebook
Continue with Google
or use

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Continue with Facebook
Continue with Google
or use

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

WindowsTechno Community

WindowsTechno Community Logo WindowsTechno Community Logo

WindowsTechno Community Navigation

  • Home
  • About Us
  • Write For Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • About Us
  • Write For Us
Home/ Questions/Q 733
Next
Answered
Vipan Kumar
  • 1
Vipan Kumar
Asked: February 17, 20232023-02-17T00:27:35+05:30 2023-02-17T00:27:35+05:30In: Active Directory

January 2023 Patch – Kerberos Hardening questions

  • 1

Hi All,

DC’s are 2016 as is functional level.

DCs are 2016

We have a legacy systems like XP,2000,2003,2008 server.

I know everyone says to decom the old servers, but our go live to replace them is like First week of april

I have not applied the patches to our DC. I also our network security:configure encryption types allowed GPO is NOT defined.

My questions are :

1 – Lets say , when applying Microsoft’s January patch it would break the Kerberos authentication for Legacy OSes ?

2 – In ADUC, can I resolve the issue by explictly setting RC4 (0x4 (RC4_HMAC_MD5)) in msDS-SupportedEncryptionTypes for the computer objects of the target ( legacy OS) ?

3- I have noticed that when I run the script I get a report that There are 63 objects that do not have AES Keys generated. How should I interpret this?

Only is it enough password reset ? how happened computer objects ? rejoin ?

4 – Do I have to change the DefaultEncryptionType in the DCs registry settings ?

HKLM\System\CurrentControlSet\Services\KDC

Value Type: REG_DWORD

Value Name: DefaultDomainSupportedEncTypes

Value : 0x3C ( AES256_CTS_HMAC_SHA1_96_SK (Session Key))

5 – AFAIK, Support for AES256_CTS_HMAC_SHA1_96_SK (Session Key) based session keys started with Windows Vista/2008, so any legacy OS prior to this date will not support this encryption type. is it enough below reg setting for legacy OS?

Value Name: DefaultDomainSupportedEncTypes

Value : 0x3C ( AES256_CTS_HMAC_SHA1_96_SK (Session Key))

 

Please help me on above my qquestions.

Thank you in Advance.

Regards

Vipan

  • 3 3 Answers
  • 83 Views
  • 0 Followers
  • 0
Share
  • Facebook

    Leave an answer
    Cancel reply

    You must login to add an answer.

    Continue with Facebook
    Continue with Google
    or use

    Forgot Password?

    Need An Account, Sign Up Here
    Continue with Facebook
    Continue with Google

    3 Answers

    • Voted
    • Oldest
    • Recent
    1. [Deleted User]
      2023-02-17T00:38:16+05:30Added an answer on February 17, 2023 at 12:38 am

      Hey , I was also looking same , help me to fix this kerberos issue permanently.

      • 0
      • Reply
      • Share
        Share
        • Share onFacebook
        • Share on Twitter
        • Share on LinkedIn
        • Share on WhatsApp
    2. Best Answer
      [Deleted User]
      2023-02-17T16:09:57+05:30Added an answer on February 17, 2023 at 4:09 pm

      There is issue with December patch as it will impact on legacy machines. Not with Jan patch

      • 0
      • Reply
      • Share
        Share
        • Share onFacebook
        • Share on Twitter
        • Share on LinkedIn
        • Share on WhatsApp
    3. Vipan Kumar
      2023-02-17T16:30:11+05:30Added an answer on February 17, 2023 at 4:30 pm

      Thank you so much , we will create gpo for RC4 encryption support.

      • 0
      • Reply
      • Share
        Share
        • Share onFacebook
        • Share on Twitter
        • Share on LinkedIn
        • Share on WhatsApp

    Sidebar

    Ask A Question

    Stats

    • Questions : 119
    • Answers : 26
    • Posts : 15
    • Comment : 1
    • Best Answers : 4
    • Users : 8
    • Groups : 2
    • Group Posts : 0
    • Popular
    • Comments
    • Tags
    • Vipan Kumar

      DFSR no longer replicates files

      • 1 Comment
    • Vipan Kumar

      Wintel Administrator Interview Questions

      • 0 Comments
    • Vipan Kumar

      What is Active Directory?

      • 0 Comments
    • Vipan Kumar

      Active Directory Domain Services Overview

      • 0 Comments
    • Vipan Kumar

      How to fix the issue with the slow authentication

      • 0 Comments
    • Manoj
      Manoj added a comment Nice explanation ? February 4, 2023 at 11:21 am

    Users

    Shawn Davis

    Shawn Davis

    • 0 Questions
    • 0 Answers
    Manoj Kumar

    Manoj Kumar

    • 0 Questions
    • 0 Answers
    Vipan Thakur

    Vipan Thakur

    • 0 Questions
    • 0 Answers

    Explore

    • Home
    • Questions

    Footer

    © 2023 WindowsTechno. All Rights Reserved
    by WindowsTechno.