<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Adfs on Cliff Hults</title><link>https://www.haguest.com/tags/adfs/</link><description>Recent content in Adfs on Cliff Hults</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cliff Hults</copyright><lastBuildDate>Fri, 20 Nov 2020 18:10:12 -0500</lastBuildDate><atom:link href="https://www.haguest.com/tags/adfs/index.xml" rel="self" type="application/rss+xml"/><item><title>ADFS &amp; CVE-2020-17049</title><link>https://www.haguest.com/posts/2020-11-20-adfs-cve-2020-17049/</link><pubDate>Fri, 20 Nov 2020 18:10:12 -0500</pubDate><guid>https://www.haguest.com/posts/2020-11-20-adfs-cve-2020-17049/</guid><description>&lt;p>Microsoft recently performed a patch for Kerberos and the KDC service on domain controllers. This would patch a heavy vulnerability in the Kerberos signing
structure. However, this presented a problem with our domain joined NAS
appliance, and disallowed any users from authenticating to SMB shares. In order
to alleviate ourselves of the issue, we followed the instructions to disable
the following registry key within &lt;code>HKLM\SYSTEM\CurrentControlSet\Services\Kdc\&lt;/code>
by adding &lt;code>PerformTicketSignature&lt;/code> set to &lt;code>DWORD 0&lt;/code>.&lt;/p></description></item></channel></rss>