ad-assurance - [AD-Assurance] RE: Questions for Microsoft?
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: Brian Arkills <>
- To: "''" <>
- Subject: [AD-Assurance] RE: Questions for Microsoft?
- Date: Mon, 25 Mar 2013 15:59:45 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport02.merit.edu; dkim=neutral (message not signed) header.i=none
Ah, I stuck some of those links in the original InCommon AD cookbook:
But it looks like the 2nd link I had included--which describes how one could execute a MITM replay against Kerberos--is now dead. A replacement link for that is at: http://csis.bits-pilani.ac.in/faculty/sundarb/courses/old/spr06/netsec/evals/project/projrefs/kerb/AIWSC03_kerberos_replay_attacks.pdf The paper suggests several possible mitigations. And note that the 1st link is one of the usual suggested mitigations, which the paper says is insufficient to protect against these attacks. RFC 4120 describes a Kerberos pre-auth framework which can be used to protect the initial session key exchange. Microsoft implements this in WS12: http://technet.microsoft.com/en-us/library/hh831747.aspx, and
conveniently turning that support on is required for many of the WS12 features. From: Brian Arkills
From:
[]
On Behalf Of Capehart,Jeffrey D Is there a list of questions for Microsoft prepared yet? Kerberos Authentication for Microsoft Active Directory http://technet.microsoft.com/en-us/library/cc780469(v=ws.10).aspx ·
Kerberos Authenticator Prevents Packet Replay [BA] Windows domain controller issued Kerberos tickets can be subjected to man-in-the-middle replay attacks, unless you've deployed WS12 domain controllers and turned on the FAST feature, sometimes also
called Kerberos armoring. Somewhere I've got a link that explains how to exploit this. And it should be easy enough to find the RFC and MS documentation that talks about this mitigating new feature/extension. |
- [AD-Assurance] Questions for Microsoft?, Capehart,Jeffrey D, 03/21/2013
- [AD-Assurance] RE: Questions for Microsoft?, Michael W. Brogan, 03/21/2013
- [AD-Assurance] RE: Questions for Microsoft?, Brian Arkills, 03/24/2013
- [AD-Assurance] RE: Questions for Microsoft?, Brian Arkills, 03/25/2013
- [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Eric Goodman, 03/27/2013
- [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Capehart,Jeffrey D, 03/27/2013
- Re: [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, David Walker, 03/27/2013
- RE: [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Ron Thielen, 03/29/2013
- RE: [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Brian Arkills, 03/29/2013
- RE: [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Ron Thielen, 03/29/2013
- Re: [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, David Walker, 03/27/2013
- [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Capehart,Jeffrey D, 03/27/2013
- [AD-Assurance] RE: Questions for Microsoft?/Matrix updates, Eric Goodman, 03/27/2013
- [AD-Assurance] RE: Questions for Microsoft?, Brian Arkills, 03/25/2013
Archive powered by MHonArc 2.6.16.