Configuring PKINIT
PKINIT (Public Key Infrastructure Initialization) enhances Kerberos authentication in Active Directory by replacing password-based authentication with certificate-based authentication. This method improves security by eliminating the need for passwords, reducing the risk of credential theft. PKINIT requires a properly configured Certificate Authority (CA) to issue certificates for both domain controllers (KDCs) and client computers. This section outlines the steps to configure PKINIT-enabled Kerberos authentication in an Active Directory environment.
Prerequisites for PKINIT Configuration¶
- A functioning Certificate Authority (CA) with a certificate template for the KDC and client computers.
- Domain controllers running Windows Server 2012 R2 or later.
- Clients with valid certificates issued by the CA.
Configuring the Certificate Authority¶
- Create Certificate Templates:
- Use the
certutiltool or the Certification Authority snap-in (certtmpl.msc) to create templates for the KDC and client computers. - Example: Create a template for the KDC with key usage
DigitalSignatureand enhanced key usageServer Authentication.
- Issue Certificates:
- Request and install certificates for domain controllers and client computers.
- Example: Use
certreqto request a certificate for a domain controller:
certreq -submit -attrib "CertificateTemplate:KDC Certificate" -config "DC01.example.com\CertServices" "KDC_Certificate.cer"
Configuring Domain Controllers for PKINIT¶
- Enable PKINIT on Domain Controllers:
- Open Active Directory Domain Services Configuration Manager and ensure the domain controller is configured to use Kerberos authentication.
-
Verify that the domain controller has a valid certificate issued by the CA.
-
Update Kerberos Settings:
- Use Group Policy to enforce PKINIT:
- Navigate to Computer Configuration > Policies > Administrative Templates > System > Kerberos.
- Enable "Use Kerberos authentication" and "Use PKINIT".
Configuring Clients for PKINIT¶
- Install Certificates:
- Ensure client computers have certificates issued by the CA.
- Example: Use
certutilto import a client certificate:
- Configure Kerberos Settings:
- Modify the registry to enable PKINIT:
- Navigate to
HKLM\SYSTEM\CurrentControlSet\Services\KDC\Parameters. - Set
UsePKINITto1.
- Navigate to
Testing PKINIT Configuration¶
- Verify Authentication:
- Use
kinitto test PKINIT authentication:
kinit -k -t "Client_Certificate.p12" [email protected]
Replace Client_Certificate.p12 with the client certificate and key file.
- Check Event Logs:
- Monitor Event Viewer for Kerberos authentication events (Event ID 4768, 4769) to confirm successful PKINIT logins.
Key takeaways¶
- PKINIT replaces password-based Kerberos authentication with certificate-based authentication, enhancing security.
- A properly configured CA and certificate templates are prerequisites for PKINIT.
- Domain controllers and clients must have valid certificates issued by the CA.
- Use Group Policy and registry edits to enable PKINIT on domain controllers and clients.
- Test PKINIT with tools like
kinitand verify logs for successful authentication.