Windows Server 2008 Kerberos Michiko Short Program Manager Microsoft Corporation.

Slides:



Advertisements
Similar presentations
The following is intended to outline our general product direction
Advertisements

Kerberos Authentication. Kerberos Requires shared secret with KDC ( perhaps not for PKINIT) Shared session key established Time synchronization needed.
Single Sign-On with GRID Certificates Ernest Artiaga (CERN – IT) GridPP 7 th Collaboration Meeting July 2003 July 2003.
Windows 2000 Security --Kerberos COSC513 Project Sihua Xu June 13, 2014.
Active Directory and NT Kerberos Rooster JD Glaser.
Technical Services & Operations WINDOWS 2008 R2 AD / DC UPGRADE PROJECT.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Windows 2000 Kerberos Interoperability Paul Hill Co-Leader, Kerberos Development Team MIT John Brezak Program Manager Windows 2000 Security Microsoft.
UNIX & W2K A single sign-on solution for a Kerberos V based AFS cell Enrico M.V. Fasanelli & Fulvio Ricciardi I.N.F.N. – Sezione di Lecce.
James Johnson. What is it?  A system of authenticating securely over open networks  Developed by MIT in 1983  Based on Needham-Schroeder Extended to.
Kerberos and PKI Cooperation Daniel Kouřil, Luděk Matyska, Michal Procházka Masaryk University AFS & Kerberos Best Practices Workshop 2006.
ACCESS CONTROL MANAGEMENT Project Progress (as of March 3) By: Poonam Gupta Sowmya Sugumaran.
15.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Use of Kerberos-Issued Certificates at Fermilab Kerberos  PKI Translation Matt Crawford & Dane Skow Fermilab.
Chapter 4 Introduction to Active Directory and Account Management
Active Directory and Windows Security Integration with Oracle Database Alex Keh Principal Product Manager, Windows and.NET Oracle.
Introduction to Kerberos Kerberos and Domain Authentication.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
SAGE Computing Services Consulting and customised training workshops Active Directory Integration AD, WLS & ADF in Harmony (a case study) Ray Tindall Senior.
Module 1: Installing Active Directory Domain Services
TAM STE Series 2008 © 2008 IBM Corporation WebSEAL SSO, Session 108/2008 TAM STE Series WebSEAL SSO, Session 1 Presented by: Andrew Quap.
Chapter 4 Introduction to Active Directory and Account Management
Slide Master Layout Useful for revisions and projector test  First-level bullet  Second levels  Third level  Fourth level  Fifth level  Drop body.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 9: Active Directory Authentication and Security.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
Microsoft SQL Server 2008 Installation Guide Omer Alrwais.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
Hands-On Microsoft Windows Server 2008
Building a KDC. Kerberos Implementations RedHat 5 comes with MIT Kerberos 1.6 Ubuntu LTS comes with MIT Kerberos Admin through CLI, but from.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
The Windows NT ® 5.0 Public Key Infrastructure Charlie Chase Program Manager Windows NT Security Microsoft Corporation.
Designing Active Directory for Security
Extending Active Directory Authentication and Account Management To Solaris 10 Systems A HOWTO guide for joining a Solaris 10 (8/07) host to a domain in.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 5 Configuring Authentication. Module Overview Lesson 1: Understanding Classic SharePoint Authentication Providers Lesson 2: Understanding Federated.
Implementing Active Directory Lesson 2. Skills Matrix Technology SkillObjective DomainObjective # Installing a New Active Directory Forest Configure a.
Windows NT ® Single Sign On Cross Platform Applications (Part II) John Brezak Program Manager Windows NT Security Microsoft Corporation.
Mastering Windows Network Forensics and Investigation Chapter 13: Logon and Account Logon Events.
SEC400 UNIX & Kerberos Interop to Achieve Identity Management
W2K and Kerberos at FNAL Jack Mark
1 Windows 2008 Configuring Server Roles and Services.
Scaling NT To The Campus Integrating NT into the MIT Computing Environment Danilo Almeida, MIT.
ACCESS CONTROL MANAGEMENT Project Progress (as of March 3) By: Poonam Gupta Sowmya Sugumaran.
Using Encryption with Microsoft SQL Server 2000 Kevin McDonnell Technical Lead SQL Server Support Microsoft Corporation.
Windows 2000 Certificate Authority By Saunders Roesser.
1 Part-1 Chap 5 Configuring Accounts Definitions.
Introduction to Active Directory Domain Services
W2K and Kerberos at FNAL Jack Schmidt Mark Kaletka.
Module 1: Implementing Active Directory ® Domain Services.
CPS Computer Security Tutorial on Creating Certificates SSH Kerberos CPS 290Page 1.
W2K Integration in the Kerberos5 based AFS cell le.infn.it Enrico M. V. Fasanelli I.N.F.N. – Sezione di Lecce Catania,
Module 2: Introducing Windows 2000 Security. Overview Introducing Security Features in Active Directory Authenticating User Accounts Securing Access to.
Installing a Domain Controller
Kerberos in an ISP environment
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
CPS Computer Security Tutorial on Creating Certificates SSH Kerberos CPS 290Page 1.
Advanced Authentication Campus-Booster ID: Copyright © SUPINFO. All rights reserved Kerberos.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
Active Directory and NT Kerberos. Introduction to NT Kerberos v5 What is NT Kerberos? How is it different from NTLM NT Kerberos vs MIT Kerberos Delegation.
Kerberos Miha Pihler MVP – Enterprise Security Microsoft Certified Master | Exchange 2010.
Overview of Active Directory Domain Services Lesson 1.
Taming the Beast How a SQL DBA can keep Kerberos under control David Postlethwaite 29/08/2015David Postlethwaite.
11 IMPLEMENTING ACTIVE DIRECTORY Chapter 2. Chapter 2: IMPLEMENTING ACTIVE DIRECTORY2 REQUIREMENTS FOR ACTIVE DIRECTORY  Microsoft Windows Server 2003.
Managing User and Service Accounts
Tutorial on Creating Certificates SSH Kerberos
Active Directory Fundamentals
VCE Dumps
Kerberos.
Presentation transcript:

Windows Server 2008 Kerberos Michiko Short Program Manager Microsoft Corporation

Agenda What’s New in Windows Vista and Windows Server 2008 Kerberos Tools Updates Configuring Interoperability with Windows

What’s New AES Support – AES256-CTS-HMAC-SHA1-96 [17] – AES128-CTS-HMAC-SHA1-96 [18] IPv6 support Support for Read Only Domain Controller (RODC) KDC returns encryption types supported by server or service Group Policy Support for Realm & Host-to-Realm settings

Kerberos AES Support ClientServerKDC Down-level Server 2008 TGT may be encrypted with AES if necessary based on policy Down-levelVistaServer 2008 Service ticket encryption in AES Vista Server 2008 All messages in AES Vista Down-level GSS encryption in AES VistaDown-levelServer 2008 AS-REQ/REP, TGS-REQ/REP in AES. Down-levelVistaDown-level No AES VistaDown-level No AES Down-level No AES For TGTs to be AES the domain must be Windows Server 2008 Functional Level.

PKInit Support for PA_PK_AS_REQ [16] & PA_PK_AS_REP [17] Support for Sha-1 Microsoft Confidential

Smart Card Support Changes Windows Server 2008 KDCs do not require the Smart Card OID User Certificates can be mapped by – UPN (supported down-level) – X.509 name – Certificate thumbprint – Subject key identifier – name

Kerberos Resources Kerberos: Windows Vista Authentication Features: en/library/f632de29-a36e-4d82-a169- 2b180deb638b1033.mspx en/library/f632de29-a36e-4d82-a169- 2b180deb638b1033.mspx MSDN Authentication: us/library/aa aspx us/library/aa aspx

Updated Tools Kerberos Setup (ksetup.exe) Kerberos Keytab Setup (ktpass.exe) SetSPN.exe

New to ksetup.exe /AddHostToRealmMap /DelHostToRealmMap /SetEncTypeAttr /GetEncTypeAttr /AddEncTypeAttr /DelEncTypeAttr

New to ktpass.exe [- /] crypto: All: All supported types

New to SetSPN.exe -F = perform the duplicate checking on forestwide level -P = do not show progress (useful for redirecting output to file) -S = add arbitrary SPN after verifying no duplicates exist -X = search for duplicate SPNs

Non-Windows Clients in Domains 1.Create new user account for host in AD – Enable AES256, if supported 2.On DC, create keytab file with ktpass 3.On host 1.Merge keytab file w/ existing 2.Edit krb5.conf to refer to DC as the Kerberos KDC 4.On both host and DC, ensure clocks are synchronized

Non-Windows Services in Domains 1.Create new user account for the service in AD Enable AES256, if supported 2.On DC, create keytab file with ktpass 3.On host, merge keytab file w/ existing keytab file on the host

Windows Clients in Realms 1.On KDC, create host principal 2.On Windows client, configure with realm settings using ksetup – Set Realm – Add KDC and Kpasswd Server (optional) If not specified, uses DNS SRV lookup – Set machine password 3.Restart client 4.On Windows client, configure account mappings

Trusts 1.On DC, configure realm with ksetup 2.On DC, create domain trust with AD Domains and Trusts MMC – If supported, enable AES256 3.On KDC, use kadmin to create cross-realm principals 4.If desired, create account mappings with AD Users and Computers MMC Advanced Features

Kerberos Resources Kerberos: Solution Guide for Windows Security and Directory Services for UNIX: amilyId=144F7B82-65CF-4105-B60C D&displaylang=en amilyId=144F7B82-65CF-4105-B60C D&displaylang=en Step-by-Step Guide to Kerberos Interoperability for Windows Server 2003 Step-by-Step Guide to Kerberos 5 (krb5 1.0) Interoperability for Windows 2000: us/library/bb aspx us/library/bb aspx

Summary What’s New in Windows Vista and Windows Server 2008 Kerberos Tools Updates Configuring Interoperability with Windows