User cannot authenticate with Kerberos with 2003 domain on 2008 (AES-128)


i have client trying connect ad establihsh trust relationship. issue during kerberos exchange client can use fips compliant encrytion (aes-128, type 17 instance). these algrithms being rejected ad when running 2003 sp server.

i upgraded server 2008 , still had same issue. when raised domain function level 2008 did start working correctly. had enabled kerberos aes-128 support account enabled fips on server , rebooted.

so guess have 2 questions.

1. first different within domain functionality between 2003 , 2008 prevent encryption algorithms being used ?

2. server 2003 or 2003 r2 offer same algorithms ? 

thanks,

g

hi,

yes, windows server 2008/vista has encryption algorithm improvement. in addition, server 2008 domain functional level can come play unified way reveal domain controllers in particular domain support aes.  single domain running @ domain functional level 2008 domain object have ms-ds-behavior-version value set reveal domain functional level show whether every computer in domain should able rely on aes encrypted tickets alone.

more information kerberos changes in windows 2008, please refer following article.

kerberos enhancements
http://technet.microsoft.com/en-us/library/cc749438(ws.10).aspx

article below provide more information:

server 2008 , windows vista: encryption better together
http://blogs.technet.com/ad/archive/2007/11/02/server-2008-and-windows-vista-encryption-better-together.aspx

thanks.


posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group