[27568] in Kerberos
Re: Bizzare problem with authenticating a service principal with AD
daemon@ATHENA.MIT.EDU (Luke Howard)
Mon Mar 12 18:26:20 2007
From: Luke Howard <lukeh@padl.com>
Message-Id: <200703122225.l2CMPRL6035755@au.padl.com>
MIME-Version: 1.0
To: tlyu@mit.edu
Date: Tue, 13 Mar 2007 09:25:27 +1100
Cc: jatestart@cs.uwaterloo.ca, kerberos@mit.edu
Reply-To: lukeh@padl.com
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
>What version of Windows is running on the AD server? One problem I
>think I've seen is that in some recent versions of Windows, AD uses a
>different salt for the password than the usual principal-name salt.
>(AD stores the actual password, rather than a key.) I thought this
>should only be a problem if you're typing a password into an MIT krb5
>ktutil or similar keytab tool, but I think ktpass may have the same
>problem.
Note that rc4-hmac keys are unsalted, and AD does store keys rather
than passwords (Windows workstations joined to a domain store the
password).
-- Luke
--
www.padl.com | www.lukehoward.com
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos