Windows 10: Windows 11 authentication with kerberos trust: date/time difference between client and server

Discus and support Windows 11 authentication with kerberos trust: date/time difference between client and server in Windows 10 Software and Apps to solve the problem; We operate a kerberos trust between our domain controllers and a Linux-based kerberos KDC for user authentication; users in Active Directory have an... Discussion in 'Windows 10 Software and Apps' started by John Perkins3, May 8, 2023.

  1. Windows 11 authentication with kerberos trust: date/time difference between client and server


    We operate a kerberos trust between our domain controllers and a Linux-based kerberos KDC for user authentication; users in Active Directory have an altSecurityIdentity field set pointing to "Kerberos:<username>@<REALM>" to authenticate user <username> via the kerberos KDC. We have a significant Linux install base, and this allows us to keep all password authentication in one source.Windows 11 clients, once joined to our domain, report "There is a time and/or date difference between the client and server." Windows 10 clients and Server 2016/2019/2022 systems authenticate as e

    :)
     
    John Perkins3, May 8, 2023
    #1
  2. Brink Win User

    Released: Microsoft Kerberos Configuration Manager for SQL Server v3.1


    Source: Released: Microsoft Kerberos Configuration Manager for SQL Server v3.1 | SQL Server Release Services
     
    Brink, May 8, 2023
    #2
  3. DimitarEX Win User
    Radius server + WLC and Client Certificate Authentication

    Hello people,

    We have an issue with our radius server.

    I will explain what is our goal and what configuration we have so far:

    Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication.

    Each client in our domain has a unique personal certificate.

    The idea is when an employee opens his PC automatically connects to the specified by the GPO recommended network by using the certificate and not the username and password.



    Currently, we configured the WLC Cisco controller to receive the client certificate, authenticate it and provide the IP address(of course if the policies are validated).

    Afterward that the WLC controller has to send the request to the radius server. The radius should check if the certificate is valid (not expired) and not included in the revocation list.

    Here our issue came. It seems that the radius cannot access the revocation list and cannot check if the certificate is revoked.

    We validated that by disabling the revocation list check in the Radius server registry settings.

    If we set it to ignore the revocation list check, the authentication succeeds, and the client is authenticated successfully.

    The thing is that this way we lower the security of the connection significantly and we would like to make sure the certificate is validated against the revocation list.

    At the same time, there are no issues in the connection between the RADIUS server and the server where the revocation list is stored/published.



    Could you please let me know if there is any specific configuration that should be made in order for the radius to be able to check the status of the authenticated certificate in the revocation list?

    Is there any configuration guide that we have to follow in order to implement the necessary configuration in the most proper way?
     
    DimitarEX, May 8, 2023
    #3
  4. Windows 11 authentication with kerberos trust: date/time difference between client and server

    Server 2019 DC - Kerberos RC4

    We have recently promoted a 2019 Server to be a domain controller but it won't authenticate access to our EMC VNX datastore which we believe only supports RC4 Kerberos -
    is there anyway to enable RC4 Kerberos in Server 2019 as it appears to have been removed?

    (Using the IIS Crypto tool we can see the 2019 server does not have any RC4 ciphers)

    Access to the EMC VNX datastore works from 2012 and 2016 DC's.

    Access from the 2019 server to all other devices on the network also work (we can see these using AES encryption via the klist utility)

    I can see no documentation suggesting any changes around Kerberos in server 2019
     
    AndySummers, May 8, 2023
    #4
Thema:

Windows 11 authentication with kerberos trust: date/time difference between client and server

Loading...
  1. Windows 11 authentication with kerberos trust: date/time difference between client and server - Similar Threads - authentication kerberos trust

  2. Windows Hello for Business and Kerberos Trust

    in Windows 10 Gaming
    Windows Hello for Business and Kerberos Trust: We're having an issue with setting up WHfB in our hybrid environment. DC is server 2016 and devices are Entra Hybrid Joined, although I've tested with an Entra joined only laptop and it's the same. The Kerberos Trust Server has been successfully set up on the DC the only one...
  3. Windows Hello for Business and Kerberos Trust

    in Windows 10 Software and Apps
    Windows Hello for Business and Kerberos Trust: We're having an issue with setting up WHfB in our hybrid environment. DC is server 2016 and devices are Entra Hybrid Joined, although I've tested with an Entra joined only laptop and it's the same. The Kerberos Trust Server has been successfully set up on the DC the only one...
  4. Protected Users and Kerberos Authentication

    in Windows 10 Gaming
    Protected Users and Kerberos Authentication: We added service accounts to protected users group and when users try to login to the server, they are getting the following error. So, I tried to ahead and create a GPO as per not allowing NTLM authentication and allowing only Kerberos authentication and denying users if...
  5. Windows 11 authentication with kerberos trust: date/time difference between client and server

    in Windows 10 Gaming
    Windows 11 authentication with kerberos trust: date/time difference between client and server: We operate a kerberos trust between our domain controllers and a Linux-based kerberos KDC for user authentication; users in Active Directory have an altSecurityIdentity field set pointing to "Kerberos:<username>@<REALM>" to authenticate user <username> via the kerberos KDC....
  6. Kerberos pre-authentication failed.

    in Windows 10 Gaming
    Kerberos pre-authentication failed.: Kerberos pre-authentication failed.Account Information: Security ID: NIACL\33338 Account Name: 33338Service Information: Service Name: krbtgt/NIACL.CO.INNetwork Information: Client Address: ::ffff:10.54.1.188 Client Port: 50207Additional Information: Ticket Options:...
  7. Kerberos pre-authentication failed.

    in Windows 10 Software and Apps
    Kerberos pre-authentication failed.: Kerberos pre-authentication failed.Account Information: Security ID: NIACL\33338 Account Name: 33338Service Information: Service Name: krbtgt/NIACL.CO.INNetwork Information: Client Address: ::ffff:10.54.1.188 Client Port: 50207Additional Information: Ticket Options:...
  8. DFS between Server and Client

    in Windows 10 Gaming
    DFS between Server and Client: Hello,Can I replicate Windows 10/11 PC folder with DFS ?I tried to add a Client PC folder and I got " Validate Path Error"DFS I tried in Win server 2008, 2019 . Both gave me same result.Please advise.ThanksCleetus...
  9. DFS between Server and Client

    in Windows 10 Software and Apps
    DFS between Server and Client: Hello,Can I replicate Windows 10/11 PC folder with DFS ?I tried to add a Client PC folder and I got " Validate Path Error"DFS I tried in Win server 2008, 2019 . Both gave me same result.Please advise.ThanksCleetus...
  10. Kerberos Pre-Authentication error

    in Windows 10 Customization
    Kerberos Pre-Authentication error: I have a Windows 10 domain joined machine that keeps throwing up Kerberos pre-authentication every 20 minutes. It is a Surface Pro machine, I tried to clear Windows cashed credentials, then I scanned the computer. I managed to disable pre-authentication for the user via the...