[18803] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: TGS-REP TICKET decrypting problem

daemon@ATHENA.MIT.EDU (Wang Weijun)
Tue Jun 10 07:06:42 2014

Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.2\))
From: Wang Weijun <weijun.wang@oracle.com>
In-Reply-To: <D7CF85FA-523B-403C-8D11-24C65793FCFF@oracle.com>
Date: Tue, 10 Jun 2014 19:06:25 +0800
Message-Id: <45A0A356-7980-47A5-A56D-06AAC9F2985E@oracle.com>
To: somenath saha <saha.somenath.88@gmail.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Good news.

The NTDSXtract tool described on the Wireshark wiki works. I am now able to decrypt an initial TGT and can confirm the session key inside is the same as the one in the AS-REP.

My AD is Windows 2008 R2.

--Max

On Jun 10, 2014, at 16:16, Wang Weijun <weijun.wang@oracle.com> wrote:

> I don't have a better answer. Maybe you can try the other tools mentioned on the page.
> 
> --max
> 
> On Jun 10, 2014, at 15:17, somenath saha <saha.somenath.88@gmail.com> wrote:
> 
>> thanks Wang. but it did not help me as ktexport doesn't work. please provide me some other solution. i'm stuck yet.
>> 
>> regards,
>> somenath
>> 
>> 
>> On Tue, Jun 10, 2014 at 10:15 AM, Wang Weijun <weijun.wang@oracle.com> wrote:
>> Windows hides the keys in a "protected storage". After some googling, I find a page showing how to reset or extract those keys. Hope it helps (I haven't tried it).
>> 
>>  http://wiki.wireshark.org/Kerberos
>> 
>> --max
> 


_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post