[24755] in Kerberos
Re: 2k3 (SP1) and PDC Emulator difference
daemon@ATHENA.MIT.EDU (Markus Moeller)
Wed Sep 28 16:55:03 2005
To: kerberos@mit.edu
From: "Markus Moeller" <huaraz@moeller.plus.com>
Date: Wed, 28 Sep 2005 21:49:18 +0100
Message-ID: <dhevl1$fbb$1@sea.gmane.org>
X-Complaints-To: usenet@sea.gmane.org
Errors-To: kerberos-bounces@mit.edu
Can you look at the error message ? I think there was a change in
calculating the salt for DES keys.
Regards
Markus
"amol dixit" <dixitamol@yahoo.com> wrote in message
news:20050928201447.43903.qmail@web52408.mail.yahoo.com...
> Hi,
> I have Windows 2k and 2k3 (SP1) AD servers in a
> domain, and if I set the 2k server as the
> OperationsMaster->PDC (aka. PDC Emulator), then
> DES_CBC_MD5 key generated using the SPN (and
> corresponding Salt) fails to authenticate on 2k3
> server. It automatically forwards the kerberos ticket
> request (AS_REQ) to the PDC Emulator (which is the 2k
> server), which in turn authenticates the SPN using the
> same key. Also, kinit can get a ticket from 2k3 for
> the same account without forwarding to PDC.
> I am at a loss to explain how come the same kerberos
> DES key works on 2k but not on 2k3, even though the
> account is created on 2k3 AD.
> Interestingly, if I make the 2k3 server as PDC master,
> it will authenticate using the same key and not
> forward the request to the 2k server anymore.
> PDC emulators are for legacy windows clients, I dont
> see what role is plays here.
> Any ideas, please let me know.
> TIA,
> Amol
>
>
>
>
> __________________________________
> Yahoo! Mail - PC Magazine Editors' Choice 2005
> http://mail.yahoo.com
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos