[22827] in Kerberos
Re: W2k3 and Hotfix KB833708
daemon@ATHENA.MIT.EDU (Markus Moeller)
Thu Nov 11 14:13:44 2004
From: "Markus Moeller" <huaraz@moeller.plus.com>
Date: Sat, 6 Nov 2004 14:48:04 -0000
Message-ID: <418ce427$0$4036$ed2619ec@ptn-nntp-reader01.plus.net>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
It seems to be related to how MS calculates salt for computer accounts in
2003, this is for example fixed in a newer Windows ktpass version. Does
anybody know how they determine the salt now ?
Thanks
Markus
"Markus Moeller" <huaraz@moeller.plus.com> wrote in message
news:4187faaa$0$4012$ed2619ec@ptn-nntp-reader01.plus.net...
>I experience problems with Hotfix KB833708 on a w2k3 kdc and MIT 1.2.4 (yes
>I know its old). The fix works fine when I use MIT 1.3.1 which supports
>RC4.
>
> When I extract a keytab which is associated with a computer account in AD
> I get decrypt integrity check failed errors. It is the same error as
> described by Nathan earkier at
> http://mailman.mit.edu/pipermail/kerberos/2004-April/005080.html. I can
> get the decrypt error solved, when I change the user account contol flag
> from UF_TRUSTED_WORKSTATION_ACCOUNT to UF_NORMAL_ACCOUNT ( I think it
> means changing it from a computer account to a user account)
>
> Has anybody experienced this too ? Do I miss another Hotfix ?
>
> Thanks
> Markus
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos