Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Active Directory Trust Question on 2008 R2 OS

Posted on 2016-10-28
3
Medium Priority
?
23 Views
Last Modified: 2016-11-16
Hi Experts,
In AD trust properties, there is a box that can be checked off called "The other domain supports Kerberos AES Encryption"...what does this actually do and what is the expected behavior if this option is checked? Please advise.

Thank you!
0
Comment
Question by:IT_Admin XXXX
  • 2
3 Comments
 
LVL 6

Assisted Solution

by:sAMAccountName
sAMAccountName earned 1000 total points (awarded by participants)
ID: 41864239
As I understand it by checking that option, you are adding AES as an accepted encryption cipher which can be used to secure the trust.  I'll let others expand if they have more information
0
 
LVL 14

Accepted Solution

by:
Dustin Saunders earned 1000 total points (awarded by participants)
ID: 41864257
The technet page is here: https://technet.microsoft.com/en-us/library/dd145414.aspx

Essentially, just says whether or not the other domain can use the AES encryption, then uses it.  As long as you are on 2008 or newer and Win7 or newer on workstations you should have no issue.  

This blog post ( https://blogs.technet.microsoft.com/enterprisemobility/2007/11/02/server-2008-and-windows-vista-encryption-better-together/ ) has some more detailed information.
1
 
LVL 14

Expert Comment

by:Dustin Saunders
ID: 41889426
Both correct answers to the question, with links to supporting documentation.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question