Re: privilege timeout

From: Doug Frisk (PublicNews_at_removeme.fazwak.com)
Date: 12/29/04


Date: Wed, 29 Dec 2004 13:10:52 -0600


"Chris" <Chris@discussions.microsoft.com> wrote in message
news:FF2890B6-A2A3-4D7A-9419-C48EFA35B647@microsoft.com...
>I am trying to configure a handful of Windows file servers to timeout user
> connections (like mapped drives) after a certain amount of idle time and
> make
> the user reauthenticate after that time is up. This is trying to mitigate
> the
> problem where a user authenticates to a sensitive file server and then
> walks
> away from the computer. I do not want to have their computer
> automatically
> lock itself...I just want that session to the sensitive file server to
> timeout and require reauthentication.

I see no point in what you're attempting to accomplish. You can tweak the
TCP parameters to cause the TCP session to time out, but when someone
*anyone* sits down at the client and attempts to access that timed out
session, the client will transparently reconnect using the same credentials
it had.

Yes, *at the server* the client will be re-authenticated, but at the client
the cached credential information is still there.



Relevant Pages

  • Re: privilege timeout
    ... >I am trying to configure a handful of Windows file servers to timeout user ... > problem where a user authenticates to a sensitive file server and then ... TCP parameters to cause the TCP session to time out, ... the client will transparently reconnect using the same credentials ...
    (microsoft.public.win2000.security)
  • Re: Using EFS with Network Shares and SFU 3.5
    ... Windows and *nix clients. ... Windows 2K3 SP1 file server that also has the NFS server component from ... when I access an encrypted file over a network share via Windows Explorer ... On my Windows XP client, I can access my home directory on the file ...
    (microsoft.public.windows.server.security)
  • Re: privilege timeout
    ... >> problem where a user authenticates to a sensitive file server and then ... >> lock itself...I just want that session to the sensitive file server to ... > *anyone* sits down at the client and attempts to access that timed out ... > the cached credential information is still there. ...
    (microsoft.public.win2000.active_directory)
  • IPSec transport mode issues between client and file server
    ... I have a Windows XP pro client and a Windows 2003 file server in the same ... which indicates a successful IKE exchange. ...
    (microsoft.public.windows.server.security)
  • Re: privilege timeout
    ... >> problem where a user authenticates to a sensitive file server and then ... >> lock itself...I just want that session to the sensitive file server to ... > *anyone* sits down at the client and attempts to access that timed out ... > the cached credential information is still there. ...
    (microsoft.public.win2000.security)