• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Heads Up! Additional Configuration Required for Windows 7/Windows Server 2008 R2

    July 14, 2010 Patrick Botz

    If you have a Windows 7 workstation or you are running Windows Server 2008 R2, there is an extra configuration step to enable Kerberos authentication with i5/OS. In these releases, Microsoft no longer enables the DES cipher suites (DES-CBC-MD5 and DES-CBC-CRC) for Kerberos by default. Unfortunately, Kerberos on i5/OS does not support the new default suites used by Microsoft.

    A few details about the Kerberos protocol will explain why this change requires additional configuration. The Kerberos protocol negotiates the cipher suites used to build Kerberos tickets. When a client requests a Kerberos ticket, it includes a list of cipher suites it supports. The Kerberos server compares this list with its own list of supported cipher suites. The first match found is the cipher suite used to build the ticket. If there is no match, the server uses its default suite.

    The cipher suites supported by i5/OS for Kerberos are:

    • DES-CBC-CRC
    • DES-CBC-MD5
    • DES-HMAC-SHA1
    • DES-CBC-SHA1

    i5/OS enables DES-CBC-CRC and DES-CBC-MD5 by default. You can choose to enable either of these suites in any order, providing, of course, that at least one of them is also supported by the KDC (i.e., Key Distribution Center or Kerberos server) used in your network.rnThe following cipher suites are enabled by default in Windows 7 and Windows Server 2008 R2:

    • AES256-CTS-HMAC-SHA1-96
    • AES128-CTS-HMAC-SHA1-96
    • RC4-HMAC

    You will notice that there are no enabled suites common to both the Microsoft environments and i5/OS. Fortunately, this is easily solved by enabling DES-CBC-MD5 and DES-CBC-CRC on Windows 7 and Windows Server 2008 R2.

    To add DES-CBC-CRC and DES-CBC-MD5 to Windows 7 or Windows Server 2008 R2, change the “Network security: Configure encryption types allowed for Kerberos” policy setting. On Windows 7 you can do this by executing gpedit.msc and expanding “Local Computer Policy” > “Computer Configuration” > “Windows Settings” > “Security Settings” > “Local Policies” > “Security Options” > “Network security: Configure encryption types allowed for Kerberos.” Once there, double-click “Network security: Configure encryption types allowed for Kerberos.” Select “DES_CBC_MD5 and DES_CBC_CRC.”

    DES-CBC-CRC is vulnerable to certain types of attacks, but it is supported–either by default or with additional configuration–by all Kerberos servers. DES-CBC-MD5 is a bit better than DES-CBC-CRC and it is widely supported by Kerberos servers. One must remember to put these vulnerabilities in perspective. For example, if you accept PUBLIC *USE or higher as the default authority of newly created objects, you are accepting much more risk than those posed by using either of these encryption suites to protect your Kerberos tickets. In addition, Kerberos tickets are relatively short-lived (and their lifetime can be reduced). Therefore, the window in which they must be captured for future manipulation is relatively small. The risk is not equivalent to that you would incur if you used these suites to protect permanently stored data.

    i5/OS allows you mange the order of the supported suites. Putting DES-CBC-MD5 ahead of DES-CBC-CRC will ensure the slightly better suite will be used for any servers that support both. In iSeries Navigator, expand “Security,” right-click on “Network Authentication Service,” and select “Properties.” On the window that pops up, select the “Tickets” tab. Remove DES-CBC-CRC and re-add it using the “Add after” button.

    The following website provides the information about the new Microsoft encryption suite defaults for Kerberos: http://technet.microsoft.com/en-us/library/dd560670(WS.10).aspx

    Patrick Botz is the principal consultant and founder of Botz & Associates Inc. He is also president of Valid Technologies, LLC, a biometric middleware ISV. Pat spent nearly 20 years working at IBM in various security roles including lead IBM i security architect, IBM eServer security team, and the head of IBM Lab Services Security Consulting practice. Check out his Website at www.botzandassociates.com. Send your questions or comments for Patrick to Ted Holt via the IT Jungle Contact page.



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Shield Advanced Solutions:  Receiver Apply Program ~ affordable availability for the IBM i
    Linoma Software:  Secure and automate data transfers with GoAnywhere Director
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Wood Distributor Shaves Inefficiencies with IBI Solution The Rest of the Power7 Lineup Is Coming August 17

    Leave a Reply Cancel reply

Volume 10, Number 21 -- July 14, 2010
THIS ISSUE SPONSORED BY:

SEQUEL Software
ProData Computer Services
System i Developer

Table of Contents

  • Heads Up! Additional Configuration Required for Windows 7/Windows Server 2008 R2
  • Who’s the Scoundrel That Corrupted My Database?
  • Admin Alert: Keep Your Data Synced Up During an HA Switch Over

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle