Problem in cryptographic protocols supported Kerberos in A.D


i have question set multi setting simultaneously domain users,
'm set user in active directory setting , enable :

 o    use kerberos des encryption types account

o   the account supports kerberos aes 128 bit encryption

i read article

http://blogs.msdn.com/b/openspecification/archive/2011/05/31/windows-configurations-for-kerberos-supported-encryption-type.aspx

but don 't know of these options applies
way
kerberos protocol can store passwords , hash in db?


mcse | mcitp [x2] | isms27001

hello -

uf_use_des_key_only bit (0x200000) in useraccountcontrol attribute of user object takes precedence pre-windows server 2008 r2 default (or if present in msdc-supportedencryptiontypes) - kerb hashes stored in secret attribute supplementalcredentials in databsae (ntds.dit): http://msdn.microsoft.com/en-us/library/cc245499.aspx

dose answer question?


enfo zipper christoffer andersson – principal advisor



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...