-
Type: Task
-
Resolution: Fixed
-
Priority: Major - P3
-
Affects Version/s: None
-
Component/s: None
-
Labels:None
-
Fully Compatible
-
Security 2019-12-16, Security 2019-12-30, Security 2019-01-13, Security 2019-01-27, Security 2020-02-10
- Linux Only
- We will recommend to users to use “Get-ADUser -Identity app1 -Properties "msDS-KeyVersionNumber"” to check the version. We do not want to query AD directly as it is a LOT of work. This does limit the effectiveness of the check though.
- Check the kvno listed in the keytab matches the kvno in Windows
- i.e. Query AD for msDS-KeyVersionNumber
- https://blogs.technet.microsoft.com/pie/2018/01/03/all-you-need-to-know-about-keytab-files/
- https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/41a643a1-e423-47ac-b77e-1a6b35c27df7