๐ Secure Bits ๐ก
๐๐ถ๐ป๐ฎ๐น ๐บ๐ผ๐ป๐๐ต๐ ๐ณ๐ผ๐ฟ ๐ฅ๐๐ฐ ๐ถ๐ป ๐๐ฒ๐ฟ๐ฏ๐ฒ๐ฟ๐ผ๐?
Microsoft is phasing out RC4 for Kerberos service tickets โ and the timeline is out.
๐ข๐ป ๐๐ฎ๐ป ๐ญ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ, an update shipped that starts the journey toward stopping default issuance of ๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐๐ถ๐ฐ๐ธ๐ฒ๐๐ with legacy encryption (like RC4). Why? Because ๐ฅ๐๐ฐ can still be selected by default depending on how your AD + service accounts are configured.
(๐๐ฑ๐ฐ๐ญ๐ฐ๐จ๐ช๐ฆ๐ด, ๐ฃ๐ถ๐ต ๐ต๐ฉ๐ช๐ด ๐ณ๐ฆ๐ข๐ญ๐ญ๐บ ๐ค๐ฐ๐ถ๐ญ๐ฅ ๐ฏ๐ฐ๐ต ๐ฃ๐ฆ ๐ด๐ฉ๐ฐ๐ณ๐ต๐ฆ๐ณ…)
โธป
๐๏ธ ๐ง๐ถ๐บ๐ฒ๐น๐ถ๐ป๐ฒ
1๏ธโฃ ๐๐ฎ๐ป ๐ญ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ โ ๐๐ป๐ถ๐๐ถ๐ฎ๐น ๐๐ฒ๐ฝ๐น๐ผ๐๐บ๐ฒ๐ป๐
๐น Adds audit/warning events forย default RC4 usage
๐น Introducesย RC4DefaultDisablementPhase
2๏ธโฃ ๐๐ฝ๐ฟ๐ถ๐น ๐ฎ๐ฌ๐ฎ๐ฒ โ ๐ฆ๐ฒ๐ฐ๐ผ๐ป๐ฑ ๐๐ฒ๐ฝ๐น๐ผ๐๐บ๐ฒ๐ป๐
๐น Accountsย withoutย msds-SupportedEncryptionTypesย are treated asย AES
๐น Effective behavior:ย RC4 no longer assumed by default
๐น If RC4 is needed:ย enable itย viaย msds-SupportedEncryptionTypes
3๏ธโฃ ๐๐๐น๐ ๐ฎ๐ฌ๐ฎ๐ฒ โ ๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐
๐น RC4DefaultDisablementPhaseย isย removed
๐น Onlyย DefaultDomainSupportedEncTypesย remains (not recommended)
โธป
๐งพย ๐ก๐ฒ๐ ๐๐๐ฒ๐ป๐ ๐๐๐
๐๐น๐ถ๐ฒ๐ป๐-๐ฟ๐ฒ๐น๐ฎ๐๐ฒ๐ฑย (client-advertised encryption types)
๐ธ ๐ฎ๐ฌ๐ญ / ๐ฎ๐ฌ๐ฏ
โข Client advertises only RC4 (Advertised Etypes)
โข Service has no msds-SET
โข DC has no DDSET
โข RC4DefaultDisablementPhase = 1
โข 201 (Warning) โ becomes 203 (Error) in Enforcement
โข Logged per request
โข Not logged if DefaultDomainSupportedEncTypes is manually defined
๐ธ ๐ฎ๐ฌ๐ฒ / ๐ฎ๐ฌ๐ด
โข Client advertises only RC4
โข AND either:
โข Service msds-SET = AES-SHA1 only, OR
โข DC DDSET = AES-SHA1 only
โข RC4DefaultDisablementPhase = 1
โข 206 (Warning) โ 208 (Error) in Enforcement
โข Logged per request
โธป
๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ-๐ฟ๐ฒ๐น๐ฎ๐๐ฒ๐ฑย (service account key material / encryption configuration)
๐ธ ๐ฎ๐ฌ๐ฎ / ๐ฎ๐ฌ๐ฐ
โข Service account key material contains only RC4 keys
โข Service has no msds-SET
โข DC has no DDSET
โข RC4DefaultDisablementPhase = 1
โข 202 (Warning) โ 204 (Error) in Enforcement
โข Not logged if DefaultDomainSupportedEncTypes is manually defined
๐ธ ๐ฎ๐ฌ๐ณ / ๐ฎ๐ฌ๐ต
โข Service account key material contains only RC4 keys
โข AND either:
โข Service msds-SET = AES-SHA1 only, OR
โข DC DDSET = AES-SHA1 only
โข RC4DefaultDisablementPhase = 1
โข 207 (Warning) โ 209 (Error) in Enforcement
โธป
๐๐ ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐ฎ๐๐ฎ๐ฟ๐ฒ๐ป๐ฒ๐๐
๐ธ ๐ฎ๐ฌ๐ฑ
โข DC HAS DDSET defined and it includes anything except AES-SHA1
โข RC4DefaultDisablementPhase = 1 or 2
โข Purpose: to highlight insecure behavior Microsoft will not โfix for youโ
โข Logged on KDCSVC start
โธป
If youโre still relying on RC4 anywhere, ๐ป๐ผ๐ ๐ถ๐ ๐๐ต๐ฒ ๐๐ถ๐บ๐ฒ ๐๐ผ ๐ณ๐ถ๐ป๐ฑ ๐ผ๐๐ where and why โ before April turns โwarningsโ into production surprises.
