[27568] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Bizzare problem with authenticating a service principal with AD

daemon@ATHENA.MIT.EDU (Luke Howard)
Mon Mar 12 18:26:20 2007

From: Luke Howard <lukeh@padl.com>
Message-Id: <200703122225.l2CMPRL6035755@au.padl.com>
MIME-Version: 1.0
To: tlyu@mit.edu
Date: Tue, 13 Mar 2007 09:25:27 +1100
Cc: jatestart@cs.uwaterloo.ca, kerberos@mit.edu
Reply-To: lukeh@padl.com
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu


>What version of Windows is running on the AD server?  One problem I
>think I've seen is that in some recent versions of Windows, AD uses a
>different salt for the password than the usual principal-name salt.
>(AD stores the actual password, rather than a key.)  I thought this
>should only be a problem if you're typing a password into an MIT krb5
>ktutil or similar keytab tool, but I think ktpass may have the same
>problem.

Note that rc4-hmac keys are unsalted, and AD does store keys rather
than passwords (Windows workstations joined to a domain store the
password).

-- Luke

--
www.padl.com | www.lukehoward.com
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post