[38069] in Kerberos

home help back first fref pref prev next nref lref last post

pbkdf2_string_to_key generating wrong encryption key

daemon@ATHENA.MIT.EDU (Ashi1986)
Tue Sep 19 08:58:47 2017

Date: Tue, 19 Sep 2017 05:58:35 -0700 (MST)
From: Ashi1986 <vermaashish_mca@hotmail.com>
To: kerberos@mit.edu
Message-ID: <1505825915309-0.post@n3.nabble.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi All , 

This is my setup . 

windows 8.1 64 bit 
windows 2012 R2 server AD and KDC . 
BS2000 with MIT kerberos 1.13.2 

I generate keytab for  SPN using this command  : 

ktpass -princ host/<Host name>@domain name -mapuser <domain name\domain user
pass> pass <password> -crypto AES256-SHA1 -ptype KRB5_NT_PRINCIPAL -out
C:\KeyTab\AES256U6.keytab 

I am trying to decrypt AP_REQ using this keytab. 
I looked at kvno, encryption type and everything else matches. 

while configuring the DES-CBC-CRC, DES-CBC-MD5, RC4-HMAC-NT it works fine
and Kerberos connection established. 

while decrypting the packet in krb5_c_decrypt -> krb5_k_decrypt ->
krb5int_dk_decrypt
returning KRB5KRB_AP_ERR_BAD_INTEGRITY? 

In case of encryption type AES128-SHA1 and AES256-SHA1, It is noticed that
keys generated from the password by using the function
[lib/crypto/krb/string_to_key.c\krb5_c_string_to_key] is different from the
key generated with the same password with KTPASS command. 

In case of DES-CBC-CRC and DES-CBC-MD5, RC4-HMAC-NT generated keys are
exactly matched with the keys generated by KTPASS command. 

Therefore kerberos connection becomes successful with the encryption type
DES-CBC-CRC, DES-CBC-MD5 and RC4-HMAc-NT and connection gets failed with
error code KRB5KRB_AP_ERR_BAD_INTEGRITY with the encryption type AES128-SHA1
and AES256-SHA1.

salt generated with MIT sources is exactly same as salt used in KTPASS
command. 

Please suggest how to fix this problem. 

Any help would be appreciated !!! 

Thanks & Regards 



--
Sent from: http://kerberos.996246.n3.nabble.com/Kerberos-General-f11810.html
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post