Solved

Active Directory Trust Question on 2008 R2 OS

Posted on 2016-10-28
3
16 Views
Last Modified: 2016-11-16
Hi Experts,
In AD trust properties, there is a box that can be checked off called "The other domain supports Kerberos AES Encryption"...what does this actually do and what is the expected behavior if this option is checked? Please advise.

Thank you!
0
Comment
Question by:IT_Admin XXXX
  • 2
3 Comments
 
LVL 6

Assisted Solution

by:sAMAccountName
sAMAccountName earned 250 total points (awarded by participants)
ID: 41864239
As I understand it by checking that option, you are adding AES as an accepted encryption cipher which can be used to secure the trust.  I'll let others expand if they have more information
0
 
LVL 12

Accepted Solution

by:
Dustin Saunders earned 250 total points (awarded by participants)
ID: 41864257
The technet page is here: https://technet.microsoft.com/en-us/library/dd145414.aspx

Essentially, just says whether or not the other domain can use the AES encryption, then uses it.  As long as you are on 2008 or newer and Win7 or newer on workstations you should have no issue.  

This blog post ( https://blogs.technet.microsoft.com/enterprisemobility/2007/11/02/server-2008-and-windows-vista-encryption-better-together/ ) has some more detailed information.
1
 
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41889426
Both correct answers to the question, with links to supporting documentation.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now