[23209] in Kerberos
Re: Login to XP workstation in WIndows Server 2003 2k3 AD domain
daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Mon Jan 17 13:55:35 2005
Message-ID: <41EC0969.2050502@anl.gov>
Date: Mon, 17 Jan 2005 12:52:25 -0600
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: Jeffrey Altman <jaltman2@nyc.rr.com>, kerberos@mit.edu
In-Reply-To: <41E92FCC.3070200@nyc.rr.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Is this a side effect of the salt contining the old principal name,
and AD storing a password? Can one tell ids the salt is correct
by looking the suggested salt in a error response to a AS_REQ?
Jeffrey Altman wrote:
> Thomas Schweizer wrote:
>
>>Note: this setup will only allow Kerberos authentication, no NTLM will
>>be available (under some circumstances Windows will transparantly fall
>>back to NTLM, e.g. if you want to access the shares of computer using a
>>plain IP-address such as \\192.168.10.12\share_name).
>>The current Samba 3.x branch doesn't support cross-realm trusts with
>>non-Windows realms, AFAIK.
>>Your KDC should be allowed to issue DES keys because I think for
>>cross-realm trusts between AD and MIT krb5 these have to be DES ones.
>
>
> Windows 2003 SP1 will support RC4-HMAC for cross-realm trusts.
> You need to use the 2003 SP1 Support Tools version of ktpass.exe
> in order to generate keytabs with RC4-HMAC keys.
>
> Something very important to note. If you turn on or off the "use
> DES only" key or change the SPN associations for an account, you
> must remember to perform a "reset password" operation on the account
> in order for the changes to work correctly.
>
--
Douglas E. Engert <DEEngert@anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos