[22133] in Kerberos
Re: Windows 2000/2003 KDCs
daemon@ATHENA.MIT.EDU (swbell)
Thu Aug 5 12:01:42 2004
From: swbell <kerygma2@swbell.net>
Message-ID: <BD37C0F3.15363%kerygma2@swbell.net>
Date: Thu, 05 Aug 2004 15:48:25 GMT
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Before a Windows server is turned into a domain controller for the first
time, there will not be any DES password hashes stored that can be used by
Kerberos. Any user added, or having the administrator change their password
AFTER the domain controller promotion will be OK.
in article 88C8B14D74194F409F0E4AEC20DF2284134845@MTLFS1.montreal.hcl.com,
"Pierre Goyette" at pierre@montreal.hcl.com wrote on 8/5/04 7:59 AM:
> Various articles mention that after you create a mapped user account in
> Windows 2000 or Server 2003 (for application servers), that you should
> change the password (I assume to the same one) once after running ktpass
> to ensure that the DES key gets created.
>
> I am trying to understand exactly what this does because I have never
> done this and everything works fine for me.
>
> Under what conditions should you do this?
>
> TIA
>
> Pierre
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos