mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-22 05:43:41 +00:00
Updated the Domain Controller requirements:
added minimum hash, and public key.
This commit is contained in:
@ -80,6 +80,8 @@ Windows Hello for Business enforces the strict KDC validation security feature,
|
|||||||
- Use the **Kerberos Authentication certificate template** instead of any other older template.
|
- Use the **Kerberos Authentication certificate template** instead of any other older template.
|
||||||
- The domain controller's certificate has the **KDC Authentication** enhanced key usage.
|
- The domain controller's certificate has the **KDC Authentication** enhanced key usage.
|
||||||
- The domain controller's certificate's subject alternate name has a DNS Name that matches the name of the domain.
|
- The domain controller's certificate's subject alternate name has a DNS Name that matches the name of the domain.
|
||||||
|
- The domain controller's certificate's signature hash algorithm is **sha256**.
|
||||||
|
- The domain controller's certificate's public key is **RSA (2048 Bits)**.
|
||||||
|
|
||||||
|
|
||||||
> [!Tip]
|
> [!Tip]
|
||||||
|
Reference in New Issue
Block a user