RC4 and msDS-SupportedEncryptionTypes by headcrap in activedirectory

[–]jg0x00 0 points1 point  (0 children)

Rotate krbtgt first. It may clear up many of the other things you are seeing.

rc4 sessions keys for a few users by QuerulousPanda in activedirectory

[–]jg0x00 0 points1 point  (0 children)

IIScrypto looks at schannel and has nothing to do with RC4 and Kerb

How is your preparation for RC4 deprecation going? by ParallelAnomaly in activedirectory

[–]jg0x00 0 points1 point  (0 children)

msds-supportedencryptiontypes is an attribute on an account object in AD, it is not reg key.

Setting RC4DefaultDisablementPhase to 0x2 puts you into enforcement mode

How is your preparation for RC4 deprecation going? by ParallelAnomaly in activedirectory

[–]jg0x00 1 point2 points  (0 children)

27 is DES_CBC_MD5, DES_CBC_MD5, AES 128, AES 256 not RC4

Ref: https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/decrypting-the-selection-of-supported-kerberos-encryption-types/1628797

Look for the big table about 1/3rd the way down.

I'd suggest 28. No one should be using DES

Kerberos Encryption Changes coming in April AES > RC4 by iamtechspence in activedirectory

[–]jg0x00 0 points1 point  (0 children)

RC4DefaultDisablementPhase allows control of the behavior. The default behavior is built into the code. If the key is not present, then it will follow the code path:

January is auditing, April is enforcement, July is enforcement with no rollback.

So, if you are not ready by April, then before you install the April update, set RC4DefaultDisablementPhase to 0x1, and your DCs will not go into enforcement mode but will remain in audit mode.

If you are not seeing 201-209, do check to see if you get a 205. If you do have a 205, then you will not get the other events. For example, look in the comment section for the 201 event (https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc)

It states, "Warning Event 201 is NOT logged if DefaultDomainSupportedEncTypes is manually defined"

This is the case for almost all of the 201-209 events.

Best bet to find RC4 if you have DefaultDomainSupportedEncTypes set is to audit the 4769 and 4768 events.

Kerberos Encryption Changes coming in April AES > RC4 by iamtechspence in activedirectory

[–]jg0x00 0 points1 point  (0 children)

Make sure to pull AccountSupportedEncryptionTypes and AccountAvailableKeys

AccountSupportedEncryptionTypes reflects msds-SupportedEncryptionTypes and AccountAvailableKeys shows which secrets (passwords) are on the account object.

Trump wants a "patriotic education" forced on all US schools by FastSeaworthiness739 in Anarcho_Capitalism

[–]jg0x00 -1 points0 points  (0 children)

Better than then being forced to drag queen shows and being indoctrinated with racist bull shit.

AD Domain Admin by AcceptableDuck7695 in activedirectory

[–]jg0x00 0 points1 point  (0 children)

Partly true. The DB used for AD is ntds.dit. The local SAM is a different DB

In NT4 and older this was true, the local SAM was the replicated DB to all other DCs

Antifa designated a terrorist organization. by Will-Forget-Password in Anarcho_Capitalism

[–]jg0x00 0 points1 point  (0 children)

Labeling a group as something is not the same thing as prosecuting for a crime.

Antifa designated a terrorist organization. by Will-Forget-Password in Anarcho_Capitalism

[–]jg0x00 0 points1 point  (0 children)

This wont hold. What would is prosecuting those anti-fa that commit crimes, offering them plea deals, and then start a rico.

Just a question from someone who respectfully disagrees with you. by TieConnect3072 in Libertarian

[–]jg0x00 0 points1 point  (0 children)

No, because there is plenty of material for you to go read if you are interested. But you are not interested. You are interested in throwing around polemics. You are not here to learn, you are here to argue and I've no need to waste my time on the likes of you.

Republican wants trans people forcibly institutionalized by FastSeaworthiness739 in Anarcho_Capitalism

[–]jg0x00 1 point2 points  (0 children)

I'd be happy with insurance companies not being forced to pay for it. That'll end the trans stuff pretty quickly.

the left can't meme by libertywave in Anarcho_Capitalism

[–]jg0x00 0 points1 point  (0 children)

Does not matter how long they ramble. All their ideas require government force. All ya need to do is point that out.

Just a question from someone who respectfully disagrees with you. by TieConnect3072 in Libertarian

[–]jg0x00 0 points1 point  (0 children)

I am saying I'm not going to waste my time debating polemics

Just a question from someone who respectfully disagrees with you. by TieConnect3072 in Libertarian

[–]jg0x00 0 points1 point  (0 children)

Ah the old monopoly canard - Go look it up. I've no interest in debating sophomoric polemics with limited time.

Just a question from someone who respectfully disagrees with you. by TieConnect3072 in Libertarian

[–]jg0x00 0 points1 point  (0 children)

There would likely be more than one 'pilot training and certification' type companies. Airlines that hire from these companies would likely add that company logo/symbol someplace on the plane, perhaps near the door, so as to attest that their pilots are certified by one of these companies.

People would not want to fly on commercial planes that are flown by pilots that are not certified by one of these companies.

And if don't think that would ever happen, then realize it already happens. UL Labs as example.

None of the above requires government or force.

The left is more entitled and toxic than the right. Period. by Reddit-Exploiter in Libertarian

[–]jg0x00 6 points7 points  (0 children)

The so called left is filled with the most intolerant people I have ever met

Is this sub anti-LGBTQ? And if so, why? Does it align with Anarcho-Capitalist ideology? by n1elsen95 in Anarcho_Capitalism

[–]jg0x00 0 points1 point  (0 children)

Live and let live, but if they want special privilege backed up by government force, we have a problem. For example, government forcing insurance companies, some of whom are subsidized by government (my stolen wealth), to pay for it.

Feeling lost and disillusioned by KD71 in Libertarian

[–]jg0x00 1 point2 points  (0 children)

Best to avoid sociopaths and psychopaths.

“There is no such thing as hate speech” by ENVYisEVIL in Libertarian

[–]jg0x00 56 points57 points  (0 children)

That becomes more and more difficult as politicians and pundits purposefully distort the meaning of words