[27733] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos for Windows NT 4.0

daemon@ATHENA.MIT.EDU (Christopher D. Clausen)
Wed May 2 22:37:36 2007

Message-ID: <8F0ED87A4D864C26A49EF1C546702A5B@CDCHOME>
From: "Christopher D. Clausen" <cclausen@acm.org>
To: "Warren Coykendall" <warren@palecek.com>
Date: Wed, 2 May 2007 21:30:53 -0500
Cc: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Warren Coykendall <warren@palecek.com> wrote:
> Hello, I was wondering we have a NT 4.0 domain which we cannot
> migrate to Windows 2003.  Is there a way to have the NT 4.0 domain
> work with Kerberos so we can get single sign-on w/out the pain of
> upgrading to active directory?

I do not think there is any Kerberos in NT 4.0.  You might be able to 
make something work with Samba though.  Are you actually running NT 4 
machines?  On Windows 2000 and above you can setup the clients to talk 
Kerberos directly to an external KDC: 
http://www.microsoft.com/technet/prodtechnol/windows2000serv/howto/kerbstep.mspx#EVCAC 
That will get you signle-sign-on, but you'll miss a lot of the other AD 
benefits.  I am of the opinion that Windows 2003 Active Directory is 
vastly superior to NT 4 domains.  I would strongly suggest using it, 
even if it is a lot of work to migrate / recreate your environment.

<<CDC 


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post