keytab file format - exporting arcfour keys from active directory

Michael B Allen mba2000 at ioplex.com
Mon May 1 18:32:40 EDT 2006


On Mon, 1 May 2006 22:32:44 +0100
"Tim Alsop" <Tim.Alsop at CyberSafe.Com> wrote:

>  * 0 2  keytype
>  * 2 2  keylen
>  * 4 keylen     keydata
>  * }
>  * POSSIBLE if length left {
>  * xxx 4        vno
>  * }
>  */
> 
> Is the "keytype" actually the key type, or is it the etype ? I ask this
> because I have seen key tables created by various products that have the
> etype stored in this field.

Keytype. At least the values I'm seeing correspond to the values seen
in ktutil list (e.g. 3 is des-cbc-md5, 23 is arcfour-hmac-md5, 16 is
des3-cbc-sha1, etc).

Mike



More information about the Kerberos mailing list