Kerberos authentication

From: Rob (Rob_at_discussions.microsoft.com)
Date: 11/18/04


Date: Thu, 18 Nov 2004 08:34:22 -0800

In the default exchange 2003 FE/BE configuration, kerberos is used for
authentication.
we have our FE in DMZ. we openedUDP/TCP 88 to our domain controllers.
we are seeing some warnings on FE:
Microsoft Exchange Server has detected that NTLM-based authentication is
presently being used between this server and server 'BE'. NTLM is still a
secure authentication mechanism and protects users' credentials. However,
this indicates that there may be a configuration issue preventing the use of
Kerberos authentication. If this condition persists, please verify that
server 'BE' is properly configured to use Kerberos authentication. After
applying any changes it may be necessary to restart Internet Information
Services on both the front-end and back-end servers.

my question is:
Do we nned to open port 88 UDP/TCP from DMZ to Back End server also?

I would greatly appreciate any help,
thanks,
Rob



Relevant Pages

  • Re: sshd: cannot disable password authentication, users canalwayslogin with password.
    ... > computer to login to the server with ssh with dsa no problem, ... > password authentication is necessary. ... > # This is the sshd server system-wide configuration file. ... > # Kerberos TGT Passing only works with the AFS kaserver ...
    (freebsd-questions)
  • Re: Kerberos logon to Terminal Server prevents folder redirection
    ... Pass-through refers to the client browser passing through credentials to the Web Interface server; so you can still use Pass-through without enabling the option "Use Kerberos authentication to connect to servers". ...
    (microsoft.public.windows.server.security)
  • Re: Outlook -> remote exchange -> always wants a password
    ... I have my server set to use Integrated Windows authentication over SSL. ... almost certainly "break" your existing users if the client setup does not ... Close out of these configuration dialogs, ...
    (microsoft.public.windows.server.sbs)
  • Re: Integrated Windows Authentication Timeout?
    ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: iis problems with some xp clients - kerberos issue?
    ... is the browser even attempting Kerberos Authentication? ... the webserver failing to get a service ticket for the SQL Server etc. ... Check that the site is in IE's Intranet zone (IE doesn't attempt to Kerberos ... Both access SQL ...
    (microsoft.public.inetserver.iis.security)