Not able to perform single sign on even while configuring the multiple encryption type using ktpass command


hello,

i trying test various encryption methods single sign on using windows ad dc server (win2012 r2), windows client machine (windows 8.1) , bs2000 machine.

we have created many keytab files various encryption types same domain user using ktpass command.

and setup kerberos key on bs2000 machine using /add-keytab-entry command , windows id access authorization defined bs2000 user id single sign on /modify-logon-protection command.

but after login in windows client machine domain user used in ktpass command and trying login bs2000 machine without password, login gets failed [with error key version mismatch or encryption type not defined].

we have configured aes128-sha1 , aes256-sha1 using ktpass command , confirmed both supported on bs2000 machine.

1. after login windows client machine using domain user used in ktpass command , windows client machine while trying login bs2000 machine, login gets failed error [with error key version mismatch or encryption type not defined]. please resolve problem.

2. while login windows client machine domain user [which used in ktpass command] , when check cached token using ktlist command ticket related encryption type aes-256-cts-hmac-sha1-96 displayed, please suggest how can use aes128-sha1 encryption instead of aes-256-cts-hmac-sha1-96.

3. can remove encryption type aes-256-cts-hmac-sha1-96 keytab files active directory therefore other encryption type can verified.

4. have configured various encryption types using ktpass command same domain user , created keytab files on ad dc server , using key version number output of ktpass command key tab entries added in bs2000 machine single sign on,

as various encryption type added single domain user and corresponding key versions added in key table of bs2000 machine, please suggest while trying perform single sign-on encryption type used , why.

thank you

hi,
since questions involves windows , non-windows environment, afraid hard supported in forum due lack of test environment, , in case, suggest open case microsoft technical support see if offer ideas: https://support.microsoft.com/en-us/contactus/?ws=support
thank understanding.
best regards,
wendy

please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file