Re: kfw-4.1: ms2mit in virtual setups?
John Devitofranceschi <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.general |
|---|---|
| Message-ID | <[email protected]> |
> On Sep 18, 2021, at 8:21 AM, John Devitofranceschi <[email protected]> wrote: > > On Sep 18, 2021, at 12:50 AM, Greg Hudson <[email protected]> wrote: >> >> On 9/17/21 5:14 PM, John Devitofranceschi wrote: >>> I can see that “AllowTGTSessionKey” is set to ‘1’ in the virtual registry. Is that not sufficient? Any way around this? >> >> The current documentation of AllowTgtSessionKey says: "With active >> Credential Guard in Windows 10 and later versions of Windows, you cannot >> enable sharing the TGT session keys with applications anymore." > > > I’ve read that too, but Credential Guard is not running, according to the “System Information” panel on our test host. > > It turns out that it works just fine if you set allowtgtsessionkey in the system registry. It is not sufficient to simply set it in the virtual registry. jd ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos
smime.p7s
(application/pkcs7-signature, 4 KB) - not displayed