{"id":733,"date":"2023-02-17T00:27:35","date_gmt":"2023-02-16T18:57:35","guid":{"rendered":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/"},"modified":"2023-02-23T23:53:21","modified_gmt":"2023-02-23T18:23:21","slug":"january-2023-patch-kerberos-hardening-questions-2","status":"publish","type":"question","link":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/","title":{"rendered":"January 2023 Patch &#8211; Kerberos Hardening questions"},"content":{"rendered":"<p>Hi All,<\/p>\n<p>DC&#8217;s are 2016 as is functional level.<\/p>\n<p>DCs are 2016<\/p>\n<p>We have a legacy systems like XP,2000,2003,2008 server.<\/p>\n<p>I know everyone says to decom the old servers, but our go live to replace them is like First week of april<\/p>\n<p>I have not applied the patches to our DC. I also our network security:configure encryption types allowed GPO is NOT defined.<\/p>\n<p>My questions are :<\/p>\n<p>1 &#8211; Lets say , when applying Microsoft&#8217;s January patch it would break the Kerberos authentication for Legacy OSes ?<\/p>\n<p>2 &#8211; In ADUC, can I resolve the issue by explictly setting RC4 (0x4 (RC4_HMAC_MD5)) in msDS-SupportedEncryptionTypes for the computer objects of the target ( legacy OS) ?<\/p>\n<p>3- I have noticed that when I run the script I get a report that There are 63 objects that do not have AES Keys generated. How should I interpret this?<\/p>\n<p>Only is it enough password reset ? how happened computer objects ? rejoin ?<\/p>\n<p>4 &#8211; Do I have to change the DefaultEncryptionType in the DCs registry settings ?<\/p>\n<p>HKLM\\System\\CurrentControlSet\\Services\\KDC<\/p>\n<p>Value Type: REG_DWORD<\/p>\n<p>Value Name: DefaultDomainSupportedEncTypes<\/p>\n<p>Value : 0x3C ( AES256_CTS_HMAC_SHA1_96_SK (Session Key))<\/p>\n<p>5 &#8211; AFAIK, Support for AES256_CTS_HMAC_SHA1_96_SK (Session Key) based session keys started with Windows Vista\/2008, so any legacy OS prior to this date will not support this encryption type. is it enough below reg setting for legacy OS?<\/p>\n<p>Value Name: DefaultDomainSupportedEncTypes<\/p>\n<p>Value : 0x3C ( AES256_CTS_HMAC_SHA1_96_SK (Session Key))<\/p>\n<p>&nbsp;<\/p>\n<p>Please help me on above my qquestions.<\/p>\n<p>Thank you in Advance.<\/p>\n<p>Regards<\/p>\n<p>Vipan<\/p>\n","protected":false},"author":1,"comment_status":"open","ping_status":"closed","template":"","question-category":[12],"question_tags":[],"class_list":["post-733","question","type-question","status-publish","hentry","question-category-active-directory"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community<\/title>\n<meta name=\"description\" content=\"January 2023 Patch - Kerberos Hardening questions\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community\" \/>\n<meta property=\"og:description\" content=\"January 2023 Patch - Kerberos Hardening questions\" \/>\n<meta property=\"og:url\" content=\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/\" \/>\n<meta property=\"og:site_name\" content=\"WindowsTechno Community\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-23T18:23:21+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/\",\"url\":\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/\",\"name\":\"January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community\",\"isPartOf\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#website\"},\"datePublished\":\"2023-02-16T18:57:35+00:00\",\"dateModified\":\"2023-02-23T18:23:21+00:00\",\"description\":\"January 2023 Patch - Kerberos Hardening questions\",\"breadcrumb\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/community.windowstechno.com\/community\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Questions\",\"item\":\"https:\/\/community.windowstechno.com\/community\/questions\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"January 2023 Patch &#8211; Kerberos Hardening questions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#website\",\"url\":\"https:\/\/community.windowstechno.com\/community\/\",\"name\":\"WindowsTechno Community\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/community.windowstechno.com\/community\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#organization\",\"name\":\"WindowsTechno Community\",\"url\":\"https:\/\/community.windowstechno.com\/community\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg\",\"contentUrl\":\"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg\",\"width\":335,\"height\":101,\"caption\":\"WindowsTechno Community\"},\"image\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community","description":"January 2023 Patch - Kerberos Hardening questions","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/","og_locale":"en_US","og_type":"article","og_title":"January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community","og_description":"January 2023 Patch - Kerberos Hardening questions","og_url":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/","og_site_name":"WindowsTechno Community","article_modified_time":"2023-02-23T18:23:21+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/","url":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/","name":"January 2023 Patch - Kerberos Hardening questions - WindowsTechno Community","isPartOf":{"@id":"https:\/\/community.windowstechno.com\/community\/#website"},"datePublished":"2023-02-16T18:57:35+00:00","dateModified":"2023-02-23T18:23:21+00:00","description":"January 2023 Patch - Kerberos Hardening questions","breadcrumb":{"@id":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/community.windowstechno.com\/community\/question\/january-2023-patch-kerberos-hardening-questions-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/community.windowstechno.com\/community\/"},{"@type":"ListItem","position":2,"name":"Questions","item":"https:\/\/community.windowstechno.com\/community\/questions\/"},{"@type":"ListItem","position":3,"name":"January 2023 Patch &#8211; Kerberos Hardening questions"}]},{"@type":"WebSite","@id":"https:\/\/community.windowstechno.com\/community\/#website","url":"https:\/\/community.windowstechno.com\/community\/","name":"WindowsTechno Community","description":"","publisher":{"@id":"https:\/\/community.windowstechno.com\/community\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/community.windowstechno.com\/community\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/community.windowstechno.com\/community\/#organization","name":"WindowsTechno Community","url":"https:\/\/community.windowstechno.com\/community\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/","url":"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg","contentUrl":"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg","width":335,"height":101,"caption":"WindowsTechno Community"},"image":{"@id":"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question\/733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/types\/question"}],"author":[{"embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/comments?post=733"}],"wp:attachment":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/media?parent=733"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question-category?post=733"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question_tags?post=733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}