Re: is it possible to change time on a few Servers?

From: Gautam Anand (gautam_at_hotpop.com)
Date: 10/04/04


Date: Tue, 5 Oct 2004 00:59:29 +0530

The AD, for security measures, relies on the times being in Synch on
all Machines (no matter what their role) for them to participate in
the domain. It allows for a skew of 5 mins I think. Anything more than
that and you would see all a lot of authentication errors on the
machines with mis-matched dates.

http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/techref/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/all/techref/en-us/W2K3TR_times_what.asp

"The Windows Time service is essential to the successful operation of
Kerberos authentication and, therefore, to Active Directory–based
authentication. Any Kerberos-aware application, including most
security services, relies on time synchronization between the
computers that are participating in the authentication request. Active
Directory domain controllers must also have synchronized clocks to
help ensure accurate data replication."

http://support.microsoft.com/default.aspx?scid=224799

http://support.microsoft.com/default.aspx?scid=kb;en-us;258059

http://www.microsoft.com/windows2000/techinfo/howitworks/security/wintimeserv.asp

-- 
Gautam Anand
e: gautam at hotpop dot com
--------------------------------- 
"Ziek" <ziek@nomail.org> wrote in message 
news:%23Smy6bkqEHA.2588@TK2MSFTNGP12.phx.gbl...
| what if I don't use this tool, what happens?
|
| These are not DC's that I am tampering with, just a few member 
servers.
| What could happen?
|
|
| "Simon Geary" <simon_geary@hotmail.com> wrote in message
| news:OYY0Yf$pEHA.592@TK2MSFTNGP11.phx.gbl...
| > Check out Time Machine: 
http://www.solution-soft.com/timemachine.shtml
| >
| > Do not change the time on any servers without using this software 
or
| > something similar, it will break Kerberos authentication.
| >
| > "Ziek" <ziek@nomail.org> wrote in message
| > news:eiRrPO%23pEHA.1296@TK2MSFTNGP12.phx.gbl...
| > >I have several servers, that for testing purposes , need to have 
their
| time
| > > changed to something like 6 months ahead of now..
| > >
| > > These servers are part of the Active Directory, but they are not 
DCs.
| > >
| > > Is this possible?
| > >
| > > Any side effects?
| > >
| > >
| >
| >
|
| 


Relevant Pages

  • Solaris Security Summary
    ... Administering Security on the Solaris OE ... Configuration control, facility management, and system ... Authentication: The ability to prove who you are. ...
    (comp.unix.solaris)
  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, how many Unix machines do you believe you would hit? ...
    (comp.sys.mac.advocacy)
  • Re: Enabling telnet, ftp, pop3 for root...
    ... Where did I say ANYTHING about not using authentication. ... You're presenting it like direct root login would be a total security ... DON'T have access to the port. ...
    (alt.os.linux)
  • Re: Cryptogram Comment
    ... Or had to go through setting up basic security for their ... > bother me with Windows questions. ... > machines are broken. ... and Linux and other open OS's make all patches FREE to redistribute. ...
    (sci.crypt)
  • Re: Temporary Ban On Links In Posts To SRI
    ... understand that there is a risk when clicking ... low)" in the general case does not apply to SRI. ... implement the security measures recommended. ... update" even with machines that are restricted to only applications ...
    (soc.religion.islam)