Closed michael-dev closed 1 year ago
KDC certificate is not checked against Domain and EKU.
Check Domain SAN and KDC EKU on KDC reply certificate.
None known.
I could also provide code to restrict the KDC cert to issuers in the LocalMachine (enterprise) NTAuth store to restrict the issuers in line with what Windows does, but am unsure if this is wanted?
I like it.
What's the problem?
KDC certificate is not checked against Domain and EKU.
What's the solution?
Check Domain SAN and KDC EKU on KDC reply certificate.
What issue is this related to, if any?
None known.