Kerberos and RC4 encryption
hi,
we have domain consists of windows 2003, 2008 , 2012 dc's. client pc's windows 7 , above. verifying security logs of dc's , cam across events below
log name: security
source: microsoft-windows-security-auditing
event id: 4769
task category: kerberos service ticket operations
level: information
keywords: audit success
user: n/a
computer: dc1.domain.com
description:
kerberos service ticket requested.
account information:
account name: hostname$@domain.com
account domain: domain.com
service information:
service name: krbtgt
service id: domain\krbtgt
network information:
client address: ::ffff:192.168.1.1
additional information:
ticket options: 0x60810010
ticket encryption type: 0x17
failure code: 0x0
transited services: -
the area of concern 1 highlighted. encryption type used 0x17 rc4 when have checked client pc windows 7. per knowledge windows 7 default use aes encryption why rc4 used. kind of events coming different user accounts , computer accounts.
Windows Server > Directory Services
Comments
Post a Comment