RE: Laptop Logoff Painfully Slow when a Kerberos Realm user is logged on



Hello Simon,

Thank you for using newsgroup!

From your post, I have performed some research but I cannot find any
similar issues reported. I notice there are some issues about MIT Kerberos
realm user's logon and access in Windows XP. For the related articles are
as below:
325468: Cannot Access Active Directory Shares From MIT Kerberos Realm
http://support.microsoft.com/kb/325468/en-us

811802: MIT Kerberos v5 Authenticated Users Cannot Access Active Directory
Resources
http://support.microsoft.com/kb/811802/en-us

825081: Cannot Use an MIT Kerberos Realm User's Cached Credentials to Log
On to a Windows XP Client
http://support.microsoft.com/kb/825081/en-us

836878: Logon failure events are incorrectly recorded for trusted MIT
Kerberos realm users
http://support.microsoft.com/kb/836878/en-us

However, I notice these issues have been resolved in Service Pack 2 for
Windows XP. If the client has not applied SP2, I suggest you first install
all updates including SP2 to see if the issue still occurs.

Download the full installation package of Windows XP Service Pack 2
<http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30
-8245-9E368D3CDB5A&displaylang=en>

Since the package is very large (about 200 -300 Mb), it will take a long
time to finish downloading using a dial-up connection. If this is the case
or there is any difficulty in downloading SP2 from our website, we can
access the following link to order a free SP2 CD to perform the
installation. It will arrive in 4 to 6 weeks since you submit the order.

Order Windows XP Service Pack 2 on CD
<http://www.microsoft.com/windowsxp/downloads/updates/sp2/cdorder/en_us/defa
ult.mspx>

Thanks & Regards,

Ken Zhao

Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security>
====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.





--------------------
| Reply-To: "Simon Collier" <simon.collier@xxxxxxxxxxxxxxxx>
| From: "Simon Collier" <simon.collier@xxxxxxxxxxxxxxxx>
| Subject: Laptop Logoff Painfully Slow when a Kerberos Realm user is
logged on
| Date: Tue, 3 Apr 2007 12:58:43 -0600
| Lines: 23
| MIME-Version: 1.0
| Content-Type: text/plain;
| format=flowed;
| charset="iso-8859-1";
| reply-type=original
| Content-Transfer-Encoding: 7bit
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Windows Mail 6.0.6000.16386
| X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6000.16386
| Message-ID: <#JkE$JidHHA.4012@xxxxxxxxxxxxxxxxxxxx>
| Newsgroups: microsoft.public.windowsxp.general
| NNTP-Posting-Host: vpn.exr.ualberta.ca 129.128.83.254
| Path: TK2MSFTNGHUB02.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP03.phx.gbl
| Xref: TK2MSFTNGHUB02.phx.gbl microsoft.public.windowsxp.general:62421
| X-Tomcat-NG: microsoft.public.windowsxp.general
|
| A laptop logoff is painfully slow when a Kerberos Realm user is logged
on.
| When we setup Windows on a brand new Dell D420 and use an MIT Kerberos
Realm
| to logon, it takes about 10 minutes to log off later (sits on the
"logging
| off" window). When we do not have the laptop setup for Kerberos, then it
| logs on and off very quickly.
|
| a. We have removed all group policies.
| b. We have tried the laptop in different OU's with different policies
| enabled.
| c. We have tried using our "standard" image for a D640 (with different
| drivers installed).
| d. We have tried a clean install of Windows from the Dell CD.
|
| If we logon as a local domain or local machine user, it works fine. If we
| setup Kerberos and logon as a MIT Kerberos Realm user, it logs on fine
but
| when it's time to log off it takes forever.
|
| We have 150+ machines on our network, all using an MIT Kerberos Realm to
| authenticate and only this one new Dell D420 has this problem, and only
when
| logging onto the domain using Kerberos Relam credentials.
|
| Has anyone seen this before?
|
|

.



Relevant Pages

  • Re: Cross Realm MIT <-> Active Directory
    ... I meant on the Unix box, not on the Windows box, so sorry on that. ... Users are defined in Active Directory ... Host and service principals are defined in MIT Kerberos (realm ... Does the Windows user XYZ need to be defined in MIT Kerberos? ...
    (comp.protocols.kerberos)
  • Re: Cross Realm MIT <-> Active Directory
    ... Users are defined in Active Directory ... Host and service principals are defined in MIT Kerberos (realm ... Now I want the Windows users to be able to login to the Unix machines( ... Does the Windows user XYZ need to be defined in MIT Kerberos? ...
    (comp.protocols.kerberos)
  • Re: cross-realm authentication problem
    ... Windows client are in KLIENT.UIB.NO, Windows user accounts are in UIB.NO, Unix/Linux machines and accounts are in UNIX.UIB.NO. ... I have one web server running RHEL4, apache 2.0.52 and Kerberos 1.3.4 as provided by Redhat, self-compiled mod_auth_kerb 5.4, and another running RHEL5, apache 2.2.3 and Kerberos 1.6.1 as provided by Redhat, self-compiled mod_auth_kerb 5.4. ... After authenticating against UIB.NO on a Linux machine (which have UNIX.UIB.NO as primary realm in krb5.conf) cross-realm authentication works fine. ... But using a Windows machine where the user is authenticated in UIB.NO I get cross-realm authentication only to the web server running RHEL4, not the one running RHEL5, I never even get a ticket for UNIX.UIB.NO from AD when trying to access the RHEL5 server web page. ...
    (comp.protocols.kerberos)
  • Re: Cross Realm MIT <-> Active Directory
    ... Now why can't user XYZ@xxxxxxxx login successfully with his Windows ... I meant on the Unix box, not on the Windows box, so sorry on that. ... user xyz can login to your Unix machine. ... Host and service principals are defined in MIT Kerberos (realm ...
    (comp.protocols.kerberos)
  • Re: Kerberos authentication NOT in AD
    ... Windows supports Unix Kerberos realms natively. ... realm user, but it's pretty easy to script such a thing or get fancy and use ... from the folks that manage the Kerberos realm, ... so I'm not doing any authentication as of yet (I've ...
    (microsoft.public.dotnet.security)

Loading