Alex Tcherniakhovski - Security

How to establish two-way trust relationship between MIT V5 Kerberos Realm and Active Directory using RC4 encryption

This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at http://www.microsoft.com/info/cpyright.htm

 

 

With the introduction of Windows 2003 SP1 it is now possible to use RC4 encryption for Kerberos exchanges between MIT V5 Realms and Active Directory as opposed, now considered to be week, DES protocol. Despite the fact that there a several good resource on the web that provide sufficient information on how to in principal establish trust between AD and MIT V5 Kerberos Realm, most of them were written prior to Windows 2003 SP1 and do not provide information on how to utilize RC4.

This walk-through attempts to bridge this gap and provide some specifics as to how to configure the trust to use RC4 encryption.

Please, follow this link for the complete walkthrough.

Published Tuesday, July 18, 2006 3:59 PM by alextch
Filed under:
Anonymous comments are disabled

© 2009 Microsoft Corporation. All rights reserved. Terms of Use  |  Trademarks  |  Privacy Statement
Microsoft
Page view tracker