[22133] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Windows 2000/2003 KDCs

daemon@ATHENA.MIT.EDU (swbell)
Thu Aug 5 12:01:42 2004

From: swbell <kerygma2@swbell.net>
Message-ID: <BD37C0F3.15363%kerygma2@swbell.net>
Date: Thu, 05 Aug 2004 15:48:25 GMT
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Before a Windows server is turned into a domain controller for the first
time, there will not be any DES password hashes stored that can be used by
Kerberos.  Any user added, or having the administrator change their password
AFTER the domain controller promotion will be OK.

in article 88C8B14D74194F409F0E4AEC20DF2284134845@MTLFS1.montreal.hcl.com,
"Pierre Goyette" at pierre@montreal.hcl.com wrote on 8/5/04 7:59 AM:

> Various articles mention that after you create a mapped user account in
> Windows 2000 or Server 2003 (for application servers), that you should
> change the password (I assume to the same one) once after running ktpass
> to ensure that the DES key gets created.
>  
> I am trying to understand exactly what this does because I have never
> done this and everything works fine for me.
>  
> Under what conditions should you do this?
>  
> TIA
>  
> Pierre
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post