[22220] in Kerberos
RE: Problem changing expired Windows 2000 passwords
daemon@ATHENA.MIT.EDU (Luke Howard)
Wed Aug 18 07:23:38 2004
From: Luke Howard <lukeh@padl.com>
Message-Id: <200408181119.VAA80592@au.padl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
To: Tim.Alsop@CyberSafe.Ltd.UK
Date: Wed, 18 Aug 2004 21:19:29 +1000
cc: kerberos@mit.edu
cc: jaltman2@nyc.rr.com
Reply-To: lukeh@padl.com
Errors-To: kerberos-bounces@mit.edu
>I am not sure if this is useful or not, but we recently noticed
>something odd when logging in with user@REALM. If you login with an
>account name of this format and the account is set to use DES keys the
>client principal name shown in Windows cache is user@domain@REALM
>instead of user@REALM ...
That's because name canonicalization is disabled for users that have
UF_USE_DES_KEY_ONLY set, even if they logon with a UPN (user@suffix).
This behaviour is incorrect according to Microsoft's own referrals
specification.
-- Luke
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos