Registry Settings related to CVE-2024-26248 and CVE-2024-29056

Anonymous
2025-02-12T14:38:26+00:00

Do REGISTRY settings for PAC validation need to be made on CLIENTS AND SERVER to test ENFORCEMENT or just the SERVER?

https://support.microsoft.com/en-us/topic/how-to-manage-pac-validation-changes-related-to-cve-2024-26248-and-cve-2024-29056-6e661d4f-799a-4217-b948-be0a1943fef1

Windows Server Identity and access Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-02-13T14:11:07+00:00

    Hello JC-RAD,

    Thank you for posting in Microsoft Community forum.

    Do REGISTRY settings for PAC validation need to be made on CLIENTS AND SERVER to test ENFORCEMENT or just the SERVER?

    A: I think just Domain Controller servers (KDC servers). The "Kerberos server" is the domain controller running the KDC service that both accepts inbound Kerberos authentication requests and is responsible for PAC validation.

    1.The KDC is a core function provided by a domain controller. Its primary role is to issue Kerberos tickets after authenticating a user’s credentials.

    2.When a client requests access to a service, the KDC issues a service ticket that includes a PAC, which contains user authorization information. The KDC (or sometimes the service that receives the ticket) then performs PAC validation to ensure that the data hasn’t been tampered with.

    3.The security update includes registry keys specifically designed to control or audit how PAC validation is performed. These keys only need to be deployed on the server that will handle these inbound Kerberos requests—that is, the domain controller acting as the KDC.

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    0 comments No comments