Kerberos and RC4 encryption


hi,

we have domain consists of windows 2003, 2008 , 2012 dc's. client pc's windows 7 , above. verifying security logs of dc's , cam across events below

log name:      security
source:        microsoft-windows-security-auditing
event id:      4769
task category: kerberos service ticket operations
level:         information
keywords:      audit success
user:          n/a
computer:      dc1.domain.com
description:
kerberos service ticket requested.

account information:
 account name:  hostname$@domain.com
 account domain:  domain.com

service information:
 service name:  krbtgt
 service id:  domain\krbtgt

network information:
 client address:  ::ffff:192.168.1.1

additional information:
 ticket options:  0x60810010
 ticket encryption type: 0x17
 failure code:  0x0
 transited services: -

 

the area of concern 1 highlighted. encryption type used 0x17 rc4 when have checked client pc windows 7. per knowledge windows 7 default use aes encryption why rc4 used. kind of events coming different user accounts , computer accounts.

what domain functional level? 2003/xp uses rc4-hmac.

http://mariusene.wordpress.com/




Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group