[23201] in Kerberos
Re: Login to XP workstation in WIndows Server 2003 2k3 AD domain
daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Sat Jan 15 10:10:11 2005
Message-ID: <41E92FCC.3070200@nyc.rr.com>
From: Jeffrey Altman <jaltman2@nyc.rr.com>
Date: Sat, 15 Jan 2005 14:57:06 GMT
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Thomas Schweizer wrote:
> Note: this setup will only allow Kerberos authentication, no NTLM will
> be available (under some circumstances Windows will transparantly fall
> back to NTLM, e.g. if you want to access the shares of computer using a
> plain IP-address such as \\192.168.10.12\share_name).
> The current Samba 3.x branch doesn't support cross-realm trusts with
> non-Windows realms, AFAIK.
> Your KDC should be allowed to issue DES keys because I think for
> cross-realm trusts between AD and MIT krb5 these have to be DES ones.
Windows 2003 SP1 will support RC4-HMAC for cross-realm trusts.
You need to use the 2003 SP1 Support Tools version of ktpass.exe
in order to generate keytabs with RC4-HMAC keys.
Something very important to note. If you turn on or off the "use
DES only" key or change the SPN associations for an account, you
must remember to perform a "reset password" operation on the account
in order for the changes to work correctly.
--
-----------------
This e-mail account is not read on a regular basis.
Please send private responses to jaltman at mit dot edu
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos