[24754] in Kerberos

home help back first fref pref prev next nref lref last post

2k3 (SP1) and PDC Emulator difference

daemon@ATHENA.MIT.EDU (amol dixit)
Wed Sep 28 16:15:42 2005

Message-ID: <20050928201447.43903.qmail@web52408.mail.yahoo.com>
Date: Wed, 28 Sep 2005 13:14:47 -0700 (PDT)
From: amol dixit <dixitamol@yahoo.com>
To: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Errors-To: kerberos-bounces@mit.edu

Hi,
I have Windows 2k and 2k3 (SP1) AD servers in a
domain, and if I set the 2k server as the
OperationsMaster->PDC (aka. PDC Emulator), then
DES_CBC_MD5 key generated using the SPN (and
corresponding Salt) fails to authenticate on 2k3
server. It automatically forwards the kerberos ticket
request (AS_REQ) to the PDC Emulator (which is the 2k
server), which in turn authenticates the SPN using the
same key. Also, kinit can get a ticket from 2k3 for
the same account without forwarding to PDC.
I am at a loss to explain how come the same kerberos
DES key works on 2k but not on 2k3, even though the
account is created on 2k3 AD.
Interestingly, if I make the 2k3 server as PDC master,
it will authenticate using the same key and not
forward the request to the 2k server anymore. 
PDC emulators are for legacy windows clients, I dont
see what role is plays here.
Any ideas, please let me know. 
TIA,
Amol



		
__________________________________ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post