Re: Datadomain Windows 2008 DC
- From: "skip" <shofmann@xxxxxxx>
- Date: Tue, 5 May 2009 09:16:10 -0700
Hello Ace
In the default DC gpo i see "Microsoft network server: digitally sign communications (always)
and
" Microsoft network server:digitally sign communications (if client agrees)
Both settings are currently enabled, do i have to disable both settings in order to allow negotiation between client and server?
"Ace Fekay [Microsoft Certified Trainer]" <aceman@xxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:uyOlvCZzJHA.5684@xxxxxxxxxxxxxxxxxxxxxxx
"Family" <shofmann@xxxxxxx> wrote in message news:%23%23XlEzYzJHA.2656@xxxxxxxxxxxxxxxxxxxxxxxyep i agree as well, i wont know what is causing this issue until i talk to support at datadomain, unfortunetly i am not the storage admin and i dont have access to the device, so i am doing what i can from an AD side to try and figure this out. I am willing to detune SMB on one of the 2008 DC's but i want to make sure this setting doesnt negetively effect other applications that are using Kerberos authentication like SQL. I assume that Kerberos authentication will still function as normal, but when making the change to SMB this will allow ntlm authentication as well, and not prevent kerberos?
Many thanks
Disabling SMB signing allows legacy and non-Windows entities to authenticate that do not support Kerberos. This will NOT stop Kerberos based clients, which will continue to authenticate using Kerberos, whether this setting is enabled or disabled.
Ace
.
- Follow-Ups:
- Re: Datadomain Windows 2008 DC
- From: Ace Fekay [Microsoft Certified Trainer]
- Re: Datadomain Windows 2008 DC
- From: skip
- Re: Datadomain Windows 2008 DC
- References:
- Re: Datadomain Windows 2008 DC
- From: Meinolf Weber [MVP-DS]
- Re: Datadomain Windows 2008 DC
- From: Paul Bergson [MVP-DS]
- Re: Datadomain Windows 2008 DC
- From: Family
- Re: Datadomain Windows 2008 DC
- From: Ace Fekay [Microsoft Certified Trainer]
- Re: Datadomain Windows 2008 DC
- Prev by Date: disable Print Screen
- Next by Date: Re: Datadomain Windows 2008 DC
- Previous by thread: Re: Datadomain Windows 2008 DC
- Next by thread: Re: Datadomain Windows 2008 DC
- Index(es):
Relevant Pages
|