{"id":16803,"date":"2020-11-18T11:36:06","date_gmt":"2020-11-18T10:36:06","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=16803"},"modified":"2022-11-03T10:36:52","modified_gmt":"2022-11-03T09:36:52","slug":"windows-out-of-band-updates-with-fix-for-kerberos-authentication-ticket-renewal-issue","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/11\/18\/windows-out-of-band-updates-with-fix-for-kerberos-authentication-ticket-renewal-issue\/","title":{"rendered":"Windows out-of-band updates with fix for Kerberos authentication ticket renewal issue"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" title=\"Update\" style=\"margin: 0px 10px 0px 0px\" border=\"0\" alt=\"Windows Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" width=\"54\" align=\"left\" height=\"54\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/11\/18\/windows-sonderupdates-fix-fr-kerberos-authentication-problem\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft has been rolling out special updates for various versions of Windows Server since November 17, 2020. These are intended to solve the problems with Kerberos authentication of ticket renewals on domain controllers.<\/p>\n<p><!--more--><\/p>\n<h2>The Kerberos authentication ticket renewal problem<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg07.met.vgwort.de\/na\/0868535ad7d54bc9bd3f4c2fd646c95c\" width=\"1\" height=\"1\">The November 2020 update <a href=\"https:\/\/support.microsoft.com\/help\/4586781\/\">KB4586781<\/a> for Windows Server, version 2004 and 20H2 fixes a number of issues (see also <a href=\"https:\/\/borncity.com\/win\/2020\/11\/11\/patchday-windows-10-updates-november-10-2020\/\">Patchday: Windows 10-Updates (November 10, 2020)<\/a>). However, in certain constellations, there were subsequently problems with Kerberos authentication on domain controllers if the update was installed on Windows Server, version 2004 and 20H2, but tickets were issued from Windows servers without this update. I had discussed this in the <a href=\"https:\/\/borncity.com\/win\/2020\/11\/16\/windows-10-windows-server-update-kb4586781-macht-probleme-mit-kerberos-dc-authentifizierung\/\">Windows 10\/Windows Server: Update KB4586781 causes issues with Kerberos DC authentication<\/a> after Microsoft <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/release-information\/status-windows-10-20h2#1522msgdesc\" target=\"_blank\" rel=\"noopener noreferrer\">posted a note<\/a> on the Windows status page. Microsoft had promised to fix it as soon as possible.<\/p>\n<h2>Microsoft releases out-of-band updates with fix<\/h2>\n<p>Microsoft has been rolling out special updates for various versions of Windows Server since November 17, 2020. I already mentioned the first update in the blog post <a href=\"https:\/\/borncity.com\/win\/2020\/11\/18\/windows-server-2012-r2-out-of-band-patch-for-kerberos-authentication-issue\/\">Windows Server 2012\/R2: Out-of-band patch for Kerberos authentication issue<\/a>. Here is now the list of updates for different Windows versions.<\/p>\n<ul>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4594442\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4594442<\/a> for Windows Server Version 1809 and Windows Server 2019\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4594439\/\">KB4594439<\/a> for Windows Server 2012 R2\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4594438\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4594438<\/a> for Windows Server 2012<\/li>\n<\/ul>\n<p>The above updates fix Kerberos authentication issues related to the value of the <em>PerformTicketSignature <\/em>registry subkey in CVE-2020-17049. The issues are related to the Windows updates of November 10, 2020. According to the respective support articles, the special update is intended to fix the following issues:<\/p>\n<ul>\n<li>Kerberos service tickets and ticket-granting tickets (TGT) might not renew for non-Windows Kerberos clients when PerformTicketSignature is set to <strong>1<\/strong> (the default).\n<li>Service for User (S4U) scenarios, such as scheduled tasks, clustering, and services for line-of-business applications, might fail for all clients when PerformTicketSignature is set to <strong>0<\/strong>.\n<li>S4UProxy delegation fails during ticket referral in cross-domain scenarios if DCs in intermediate domains are inconsistently updated and PerformTicketSignature is set to <strong>1<\/strong>.<\/li>\n<\/ul>\n<p>The updates are available in the <a href=\"http:\/\/www.catalog.update.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> (search for the KB number). Microsoft recommends installing the last Servicing Stack Update (SSU) according to ADV990001, before installing the patch. Problems are not known yet. Details can be found in the respective support articles.  <\/p>\n<p><strong>Similar articles:<\/strong><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/11\/11\/patchday-windows-10-updates-november-10-2020\/\">Patchday: Windows 10-Updates (November 10, 2020)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/11\/16\/windows-10-windows-server-update-kb4586781-macht-probleme-mit-kerberos-dc-authentifizierung\/\">Windows 10\/Windows Server: Update KB4586781 causes issues with Kerberos DC authentication<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/11\/18\/windows-server-2012-r2-out-of-band-patch-for-kerberos-authentication-issue\/\">Windows Server 2012\/R2: Out-of-band patch for Kerberos authentication issue<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft has been rolling out special updates for various versions of Windows Server since November 17, 2020. These are intended to solve the problems with Kerberos authentication of ticket renewals on domain controllers.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,22,2],"tags":[399,195,159],"class_list":["post-16803","post","type-post","status-publish","format-standard","hentry","category-issue","category-update","category-windows","tag-fix","tag-update","tag-windows-server"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=16803"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/16803\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=16803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=16803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=16803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}