NT workstations unable to change domain password.

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Chris Arnold (ChrisArnold_at_discussions.microsoft.com)
Date: 08/10/04


Date: Tue, 10 Aug 2004 12:45:03 -0700

I have 40 some NT 4.0 workstations left on my network (All service pack 6a).
The servers are all 2000 (service pack 4) using Active Directory in native
mode (Not Mixed Mode) with one global catalog server at each of 10
sites/subnets/branches. The NT workstations have no problem logging on;
however, if they are not in the same subnet/site/branch as the server running
the PDC emulator, they get error: “C00000BE” when attempting a password
change. 4.0 machines on the same subnet have no problem changing passwords.

I’ve scanned the Web for this problem but have found no resolution. IP
connectivity is good (T1’s and Higher). There are only about a 100 machines
total in the network. The PDC machine is running some web hosting for our
internal intranet, but I don’t think it’s overloaded. I have added the
MaxPacketSize parameter to the Kerberos parameters to force TCP rather than
UDP during authentication. The other articles I found talk about parameters,
which, if not set correctly, should stop all 4.0 machines from changing their
passwords not just ones on another subnet.

This one has me stumped. Any help would be appreciated.

Chris Arnold
     



Relevant Pages

  • Re: unified authentication
    ... > I have a number of FreeBSD machines. ... Each *class* of server or device gets a different root password (or ... root/enable passwords, and have a bit less worry about ex-employees. ... only sysadmins have logins on routers.) ...
    (FreeBSD-Security)
  • NT 4.0 Workstations unable to change passwords
    ... mode (Not Mixed Mode) with one global catalog server at each of 10 ... if they are not in the same subnet/site/branch as the server running ... machines on the same subnet have no problem changing passwords. ...
    (microsoft.public.win2000.active_directory)
  • Re: Automatic Client Login
    ... client data, I was hoping there was at least a way to allow printing (the ... I am terribly new to server based networks and SBS is my first experience ... manner as the other four machines) that I can't join the Pro box to the ... physical security if you save the passwords on the machines. ...
    (microsoft.public.windows.server.sbs)
  • yp troubles
    ... I've tried several times to get NIS to allow me to update passwords ... from any of my machines and I still haven't gotten it to work. ... On a client machine, I can run yppasswd and update ... Problem two occurs on the server. ...
    (comp.os.linux.networking)
  • Re: Automatic Client Login
    ... You then set up workstations with usernames/passwords that match the usernames/passwords on the server. ... I have a hardware firewall and then my SBS still has two nics and does another firewall duty. ... I just tried connectcomputer on the Pro machine, and it seems due to the topology of my network between the WAN and the LAN (the server is physically connected to the router in the same manner as the other four machines) that I can't join the Pro box to the domain. ... You run the risk of lack of physical security if you save the passwords on the machines. ...
    (microsoft.public.windows.server.sbs)