Use of Kerberos unreliable, can I force it?

Use of Kerberos unreliable, can I force it?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Use of Kerberos unreliable, can I force it? NoelByron 07-17-2008
Posted by on July 17, 2008, 5:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi!

I had to learn that it is easily possible for clients in our network
to work without Kerberos (tickets). Mostly because they boot their
computer without a network connection. Those users have no Kerberos
tickets (of course) but they don=92t get Kerberos tickets even after
connection to our network (bug or feature?). There are also some other
scenarios in which Windows relinquishes Kerberos. The problem is that
we have some web applications that require a Kerberos ticket.

My question: How can I switch on Kerberos as soon as they connect to
the network? Or how can I force Kerberos authentication in a web
application (SharePoint). Integrated Windows Authentication means NTLM
or Kerberos=85

Tips would be highly appreciated. Thanks in advance!

Best regards,
Noel

Posted by S. Pidgorny on July 17, 2008, 9:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You can't. We have been asking this of Microsoft for quite a while now.

As to the users not getting tickets after connecting to the network, that is
a problem. Maybe related to your configuration but also can be caused by a
bug - there are quite a few KB articles and hotfixes for Kerberos.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

Hi!

I had to learn that it is easily possible for clients in our network
to work without Kerberos (tickets). Mostly because they boot their
computer without a network connection. Those users have no Kerberos
tickets (of course) but they don’t get Kerberos tickets even after
connection to our network (bug or feature?). There are also some other
scenarios in which Windows relinquishes Kerberos. The problem is that
we have some web applications that require a Kerberos ticket.

My question: How can I switch on Kerberos as soon as they connect to
the network? Or how can I force Kerberos authentication in a web
application (SharePoint). Integrated Windows Authentication means NTLM
or Kerberos…

Tips would be highly appreciated. Thanks in advance!

Best regards,
Noel



Similar ThreadsPosted
Force reboot in WSUS September 22, 2005, 3:55 pm
"Force shutdown from a remote system" October 13, 2006, 3:26 pm
Virtual Task Force Nabs 565 Cyber Criminals May 23, 2006, 7:18 pm
How to force a (the same !) user to logon when connecting to a network shared folder ? March 4, 2007, 8:19 am
Kerberos UDP vs TCP November 14, 2006, 4:18 am
Kerberos Delegation July 6, 2005, 2:06 pm
Bug in Kerberos SSP within SSPI?? July 28, 2005, 4:46 am
Kerberos problem April 22, 2008, 1:02 pm
how Lsass & Kerberos works ? July 8, 2005, 5:45 am
How to set up Kerberos authentication? (some code :) August 18, 2005, 5:55 pm

The site map in XML format XML site map

Contact Us | Privacy Policy