Re: active directory - kerberos realms

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 05/15/04


Date: Sat, 15 May 2004 08:17:40 -0400

You can use an MIT or Heimdahl implementation instead of AD kerberos but not on
the domain controller, you would set up a different realm entirely. You would
lose many of the Microsoft benefits such as the built in authorization, group
policies, integrated LDAP directory, etc.

You can also set up an MIT/Heimdahl realm and have the AD domains trust it and
have clients authenticate to that. It is considerable work.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
barabba wrote:
> Hi all,
> 
> we all know that Active Directory uses Kerberos for a number of
> things.
> We also all know that all Domain Controllers run Kerberos by default.
> 
> However, I read in a MS book that it is possible to use third pary
> Kerberos service instead of the native Kerberos supplied by DCs.
> Is this true ?
> Does anybody have any more details about this ?
> 
> Thanks,
> Bar


Relevant Pages

  • Re: NTLM and Kerberos
    ... I would have to open port 88 to my Domain Controller? ... How would IE know which server is the Domain Controller (my home computer is ... Kerberos requires the user to obtain a Kerberos Service Ticket for the ... even attempt Kerberos authentication for sites in the Internet zone. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... Kerberos result when I hardwired a laptop to a switch port. ... to authenticate with K on reboot AND authentication appears to take place ... > denied access until you can authenticate to a domain controller as a user. ... > You should have logging of account logon events enabled in Domain Controller ...
    (microsoft.public.windows.server.security)
  • Re: Account lockouts help
    ... Kerberos does not have a ticket for host/%2003 server FQDN% ... > computer and a Windows 2003 domain controller in a normal configuration ... > the support tools netdiag, dcdiag, and gpotool on your domain controllers ...
    (microsoft.public.security)
  • Re: kerberos problem
    ... i already disabled that domain controller group policy option. ... Since I am getting this Kerberos error on the mac... ... It also doesn't let me authenticate with Entourage to the same server. ... I CAN connect using Remote Desktop Connection from the Mac which does not seem to use Kerberos when connecting. ...
    (microsoft.public.win2000.security)
  • Re: Exchange hates me!
    ... >> mailbox I receive no errors and both boxes are updated accordingly, ... > tme used b the Kerberos server you won't get a security ticket. ... > the same network segment that's not usually a problem. ... Domain Controller. ...
    (microsoft.public.exchange.admin)