Lars Schimmer
Fri, 26 Jul 2013

On 2013-07-26 12:56, Jeffrey Altman wrote:

> What are the enctypes of the service tickets obtained on the Windows
> systems that do not work?   The enctypes from a service ticket on Linux=

> using the old client using the old algorithm are not comparable.

Ok, now with access to such a machine:
Etype (skey, tkt): AES-256 CTS mode with 96-bit SHA-1 HMAC, AES-256 CTS
mode with 96-bit SHA-1 HMAC
Etype /skey, tkt): DES cbc mode with CRC-32, AES-256 CTS mode with
96-bit SHA-1 HMAC

On the working machine the AES-256 CTS is also some kind of DES.
Interesting why one of three get 2 DES and non AES....

But yeah, that looks like new client tries to use AES-256 and fail.

