@fabian_bader@seccubus@fabian_bader maybe we can set this on DC’s (and clients), haven’t tested that yet (to fix pre-authentication failure);
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\DefaultEncryptionType (reg_dword) default is 23 (dec) RC4; change to 24 (dec) AES ?
@fabian_bader@seccubus The KRB-AS-REQ failure was coming from a computer account, having 24 as set via GPO for Kerberos encryption types, only AES e-types are configured.
@fabian_bader@seccubus@fabian_bader another interesting find, AS requests fail with DES. This happens where the krbtgt account has msDS-SupportedEncryptionTypes set to 0x0. Clearing this flag seems to be the fix (still investigating and testing).
@fabian_bader@seccubus Indeed, got it. 56 sounds like the best option 111000, only AES but pre-authentication fails without RC4 enabled. As a workaround: 60 for now. So a new update will be published, is this (officially) confirmed by Microsoft?
@fabian_bader@seccubus Ah I see the only two options to disable RC4 are 8 and 24, causing pre-authentication to fail! So the default should be 63 instead of 39, is that correct? @fabian_bader
@fabian_bader@seccubus To be honest I wouldn’t choose 39, as default, that would enable DES. The least bits should be binary 0000 to prevent that. So 24 (0x18) or 46 (0x2E) seems more appropriate to disable RC4 and DES for session key encryption. Or the same as your allowed Kerberos encryption types.
@perttuasdf@seccubus I have the impression (observing the requested encryption types) Microsoft accidentally mixed dec and hex for default KDC value 27 DefaultDomainSupportedEncTypes. Or some other logic flaw. Can someone acknowledge this?
Are you experiencing #Kerberos issues after patching for #CVE-2022-37966? My Schuberg Phils colleague Matthijs may have found the solution for you. https://t.co/e2NvXJQoFj
@perttuasdf@seccubus That behavior seems to be different starting with Windows server 2019.
Luckily DES is rejected, strange why this setting would be defaulting to 27 instead of 24.
@sixtyvividtails@msftsecresponse I had the same thought too. Reading other advisories for ms15-078 and ms16-132, they contain the same regkey DisableATMFD. ‘Windows 8.1 and below’ should read ‘Windows 8.1 and newer’, right @msftsecresponse ?
One of the most challenging circuits on the calendar - it's #SingaporeGP week! 🇸🇬
@FlorisWijers takes us around a lap of Marina Bay on the @Formula1game #HaasF1
De mooiste zin uit het boek van Rian van Rijbroek tot nu toe. De uitleg over de cloud: Het is een geheel van hardware en software waarmee computer- capaciteit wordt opgewekt.
Deze editie van de Stelvio for Life was een memorabele met zon, regen, wind, mist en sneeuw en gaat de boeken in als een van de zwaarste edities. We zijn enorm trots op alle deelnemers. Wat een bedrag!! €591.284,52 #goeddoel#kanker#stelvio