Skip to content

Configuring PKINIT

PKINIT (Public Key Infrastructure Initialization) enhances Kerberos authentication in Active Directory by replacing password-based authentication with certificate-based authentication. This method improves security by eliminating the need for passwords, reducing the risk of credential theft. PKINIT requires a properly configured Certificate Authority (CA) to issue certificates for both domain controllers (KDCs) and client computers. This section outlines the steps to configure PKINIT-enabled Kerberos authentication in an Active Directory environment.

Prerequisites for PKINIT Configuration

  • A functioning Certificate Authority (CA) with a certificate template for the KDC and client computers.
  • Domain controllers running Windows Server 2012 R2 or later.
  • Clients with valid certificates issued by the CA.

Configuring the Certificate Authority

  1. Create Certificate Templates:
  2. Use the certutil tool or the Certification Authority snap-in (certtmpl.msc) to create templates for the KDC and client computers.
  3. Example: Create a template for the KDC with key usage DigitalSignature and enhanced key usage Server Authentication.

certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2
This enables support for Subject Alternative Name (SAN) in certificate templates.

  1. Issue Certificates:
  2. Request and install certificates for domain controllers and client computers.
  3. Example: Use certreq to request a certificate for a domain controller:
certreq -submit -attrib "CertificateTemplate:KDC Certificate" -config "DC01.example.com\CertServices" "KDC_Certificate.cer"

Configuring Domain Controllers for PKINIT

  1. Enable PKINIT on Domain Controllers:
  2. Open Active Directory Domain Services Configuration Manager and ensure the domain controller is configured to use Kerberos authentication.
  3. Verify that the domain controller has a valid certificate issued by the CA.

  4. Update Kerberos Settings:

  5. Use Group Policy to enforce PKINIT:
    • Navigate to Computer Configuration > Policies > Administrative Templates > System > Kerberos.
    • Enable "Use Kerberos authentication" and "Use PKINIT".

Configuring Clients for PKINIT

  1. Install Certificates:
  2. Ensure client computers have certificates issued by the CA.
  3. Example: Use certutil to import a client certificate:
certutil -addstore -user My "Client_Certificate.cer"
  1. Configure Kerberos Settings:
  2. Modify the registry to enable PKINIT:
    • Navigate to HKLM\SYSTEM\CurrentControlSet\Services\KDC\Parameters.
    • Set UsePKINIT to 1.

Testing PKINIT Configuration

  1. Verify Authentication:
  2. Use kinit to test PKINIT authentication:
kinit -k -t "Client_Certificate.p12" [email protected]

Replace Client_Certificate.p12 with the client certificate and key file.

  1. Check Event Logs:
  2. Monitor Event Viewer for Kerberos authentication events (Event ID 4768, 4769) to confirm successful PKINIT logins.

Key takeaways

  • PKINIT replaces password-based Kerberos authentication with certificate-based authentication, enhancing security.
  • A properly configured CA and certificate templates are prerequisites for PKINIT.
  • Domain controllers and clients must have valid certificates issued by the CA.
  • Use Group Policy and registry edits to enable PKINIT on domain controllers and clients.
  • Test PKINIT with tools like kinit and verify logs for successful authentication.