[23209] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Login to XP workstation in WIndows Server 2003 2k3 AD domain

daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Mon Jan 17 13:55:35 2005

Message-ID: <41EC0969.2050502@anl.gov>
Date: Mon, 17 Jan 2005 12:52:25 -0600
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: Jeffrey Altman <jaltman2@nyc.rr.com>, kerberos@mit.edu
In-Reply-To: <41E92FCC.3070200@nyc.rr.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Is this a side effect of the salt contining the old principal name,
and AD storing a password? Can one tell ids the salt is correct
by looking the suggested salt in a error response to a AS_REQ?


Jeffrey Altman wrote:
> Thomas Schweizer wrote:
> 
>>Note: this setup will only allow Kerberos authentication, no NTLM will 
>>be available (under some circumstances Windows will transparantly fall 
>>back to NTLM, e.g. if you want to access the shares of computer using a 
>>plain IP-address such as \\192.168.10.12\share_name).
>>The current Samba 3.x branch doesn't support cross-realm trusts with 
>>non-Windows realms, AFAIK.
>>Your KDC should be allowed to issue DES keys because I think for 
>>cross-realm trusts between AD and MIT krb5 these have to be DES ones.
> 
> 
> Windows 2003 SP1 will support RC4-HMAC for cross-realm trusts.
> You need to use the 2003 SP1 Support Tools version of ktpass.exe
> in order to generate keytabs with RC4-HMAC keys.
> 
> Something very important to note.  If you turn on or off the "use
> DES only" key or change the SPN associations for an account, you
> must remember to perform a "reset password" operation on the account
> in order for the changes to work correctly.
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post