Domain Controllers
Active Directory (AD) relies on Domain Controllers (DCs) as the core infrastructure for managing authentication, directory services, and network resources. DCs host the Active Directory Domain Services (AD DS) role and act as the authoritative source for directory data. They also provide critical services such as LDAP, DNS, and Kerberos, which underpin AD’s functionality and security model. Understanding these roles is foundational for both defensive analysis and offensive exploitation in AD environments.
Domain Controller Overview¶
A Domain Controller is a server that runs the AD DS role and maintains a copy of the AD database. Key responsibilities include:
- Authentication and Authorization: Validating user credentials and enforcing access control policies.
- Directory Management: Storing and managing objects (users, groups, computers) and their attributes.
- Replication: Synchronizing directory data across DCs to ensure redundancy and fault tolerance.
Each DC in a domain is part of a domain functional level, which determines the features and capabilities available (e.g., Windows Server 2016 or later). DCs also participate in forest trusts and domain trusts to enable cross-domain communication.
LDAP Service: Directory Access Protocol¶
LDAP (Lightweight Directory Access Protocol) enables clients to query and modify directory data stored in AD. DCs act as LDAP servers, exposing the directory via:
- Port 389 (unencrypted) or Port 636 (LDAPS, encrypted with TLS).
Key LDAP operations in AD:
- Search: Retrieve user/group attributes (e.g., CN=Users).
- Bind: Authenticate users or services against the directory.
- Modify: Update object properties (e.g., password changes).
Example: Querying user information using ldapsearch:
Security Considerations: LDAP is vulnerable to sniffing and brute-force attacks. Always use LDAPS with strong TLS configurations.
DNS Service: Name Resolution and Service Discovery¶
DCs act as DNS servers and DNS clients, ensuring seamless network communication. Key roles include:
- Service Location: Resolving Service Principal Names (SPNs) for Kerberos authentication.
- Replication: Using DNS SRV records to locate DCs and other services (e.g., _ldap._tcp.dc._dc).
- Global Catalog: Advertising GC servers for efficient directory queries.
Example: Resolving a DC’s DNS record:
Security Considerations: Misconfigured DNS records can enable DNS spoofing or SPN hijacking. Validate DNSSEC and monitor for unauthorized SRV records.
Kerberos Service: Authentication Protocol¶
Kerberos is the primary authentication protocol in AD, managed by DCs as the Key Distribution Center (KDC). Key components:
- Ticket Granting Ticket (TGT): A credential issued to users after successful authentication.
- Service Tickets: Used to access network resources (e.g., file shares, printers).
- ** krbtgt Account**: A privileged account storing the encryption key for the Kerberos realm.
Kerberos Workflow:
1. User requests a TGT from the KDC.
2. KDC issues a TGT encrypted with the user’s password hash.
3. User requests a service ticket using the TGT.
4. Service validates the ticket and grants access.
Example: Checking Kerberos tickets with klist:
Security Considerations: Compromising the krbtgt account enables pass-the-ticket attacks. Always protect the Kerberos realm with strong passwords and monitor for ticket reuse.
Replication and Other Services¶
- File Replication Service (FRS): Used in older AD versions to replicate the directory database.
- DFS Replication (DFSR): Replaced FRS in Windows Server 2008 and later for more efficient replication.
- SYSVOL: A shared folder containing Group Policy Objects (GPOs) replicated across DCs.
Replication ensures high availability and consistency across DCs. Misconfigurations in replication can lead to split-brain scenarios or data loss.
Key takeaways¶
- Domain Controllers are the backbone of AD, managing authentication, directory data, and network services.
- LDAP enables directory access, DNS ensures service discovery, and Kerberos secures authentication.
- Replication and secure configuration of these services are critical for AD resilience and security.
- Understanding these roles is essential for both defending against and exploiting AD environments.