Re: kerberos



when talking about Windows machines you can only use kerberos on
Windows 2000 and up computers in an Active Directory forest. Those
machines in a AD forest will use kerberos by default. computers ar in
a NT4 domain NTLM will be used for authentication. If you have NT4
servers in a AD forest/domain, again NTLM will be used. Using Kerberos
or NTLM depends on the OS of the machines that talk to each other
WITHIN a AD forest and which of the two is the weakest link.


Ok, thanks. I've no experience with Windows servers, so I'll have to start from te beginning with this.
.




Relevant Pages

  • RE: Re[2]: [Full-Disclosure] Security aspects of time synchronization infrastructure
    ... least the MS machines that are part of it). ... assuming the time change would sync across the forest I would guess ... I am not sure how kerberos ... However the forest would be up and functioning in terms of authentication, ...
    (Full-Disclosure)
  • RE: Re[2]: [Full-Disclosure] Security aspects of time synchronization infrastructure
    ... least the MS machines that are part of it). ... assuming the time change would sync across the forest I would guess ... I am not sure how kerberos ... However the forest would be up and functioning in terms of authentication, ...
    (Full-Disclosure)
  • Re: Creating/editing user accounts
    ... Subject: Creating/editing user accounts ... useful setting, but in a DMZ forest, I'd be removing that right immediately. ... The last thing I would want is some malicious d00d adding his machines to my ...
    (Focus-Microsoft)
  • Re: Assigned = yes installed=no different subnets,site and domain
    ... > For one the staff machines h+ave a differents naming scheme and two they also have a different IP Scheme. ... >> It is not supported for a site in one forest to have site systems in another>> forest. ... >> This posting is provided "AS IS" with no warranties, ... Will i be able to install the>> client and manage them. ...
    (microsoft.public.sms.setup)
  • Re: Assigned = yes installed=no different subnets,site and domain
    ... This posting is provided "AS IS" with no warranties, ... > For one the staff machines h+ave a differents naming scheme and two they ... >> forest. ... >> using the Client push technology on both the staff ans student machines. ...
    (microsoft.public.sms.setup)

Loading