Re: Using Kerberos in Windows 2000 Clustering

From: Mike Rosado [MSFT] (mikeros_at_online.microsoft.com)
Date: 09/20/04


Date: Mon, 20 Sep 2004 07:01:25 -0500

Hi Shaun,

As stated in the following article, clients prior to Windows 2000 do not
support Kerberos. Because Kerberos was implemented as of Windows 2000 SP3
and later.

299656 How to prevent Windows from storing a LAN manager hash of your
password
http://support.microsoft.com/?id=299656

I'm by no means an expert in this subject matter of Exchange, but I'll try
to assist you to the best of my ability. My understanding is that Exchange
does support Kerberos if it's installed or client OS are Windows 2000 SP3
and greater.

-- 
Hope this helps,
Mike Rosado
Windows 2000 MCSE + MCDBA
Microsoft Enterprise Platform Support
Windows NT/2000/2003 Cluster Technologies
====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
<http://www.microsoft.com/info/cpyright.htm>
-----Original Message-----
"Shaun Rumbelow" <shaun.rumbelow@sth.nhs.uk.donotspam> wrote in message
news:70B4A9A3-060B-4259-8627-F3B1E416FC9D@microsoft.com...
> Hi,
>
> We have several clusters running Windows 2000 Advanced Server SP3. The
> various clusters run Exchange 2000, SQL 2000 and File shares. KB235529
> mentions that the clusters can use kerberos (if turned on) as stated
below. I
> also believe that Windows 2003 clustering has Kerberos turned on by
default -
> we are planning to upgrade some of the clusters to Windows 2003 and
Exchange
> 2003.
>
> My questions are:
>
> 1) Can 95 and 98 clients still use the cluster resources such as file
shares
> - can the clients still use LM rather than Kerberos? If so does this apply
to
> Windows 2000 and Windows 2003.
>
> 2) Am I correct in thinking that Exchange 2000 doesn't use kerberos and
thus
> kerberos couldn't be configured on the cluster servers? Does Exchange 2003
> allow for kerberos and again can 9x clients use this.
>
> Any help would be appreciated
>
> KB235529
> "This article describes the Kerberos authentication support for Windows
> 2000-based server clusters that has been added in Windows 2000 Service
Pack 3
> (SP3). With versions of Windows 2000 earlier than SP3, the Cluster service
> does not publish Computer objects for virtual servers in Active Directory.
> This means that virtual servers authenticate only by using NTLM or NTLM
> version 2. With Windows 2000 SP3, you can configure virtual servers to
permit
> clients to authenticate by using the Kerberos authentication protocol. If
> this is enabled, a Computer object is created for each corresponding
Network
> Name resource.
>
> Kerberos authentication for the Network Name resource on which Microsoft
> Exchange 2000 depends is not supported on a server cluster. Exchange 2000
was
> not tested with the expectation that a cluster virtual server would
support
> Kerberos authentication; this configuration may not function properly.
Future
> versions of Exchange Server may take advantage of Kerberos authentication
for
> server clusters. "
>
>
> -- 
> Thanks for your help
> Shaun Rumbelowshaun.rumbelow@sth.nhs.uk.donotspam


Relevant Pages

  • RE: kfw-3.2-beta2 is available
    ... The MIT Kerberos Development Team and Secure Endpoints Inc. are proud to ... The use of ellipsis on menu items now follows the Windows ... The alternate is to open the new credentials ... Network Identity Manager Kerberos v5 Support ...
    (comp.protocols.kerberos)
  • kfw-3.2-beta1 is available - corrected MSI
    ... The MIT Kerberos Development Team and Secure Endpoints Inc. are proud to ... The use of ellipsis on menu items now follows the Windows ... The alternate is to open the new credentials ... Support per-realm settings. ...
    (comp.protocols.kerberos)
  • Kerberos for Windows 3.2 is released
    ... The MIT Kerberos Development Team and Secure Endpoints Inc. are proud to ... Supported Versions of Microsoft Windows ... Binaries and source code can be downloaded from the MIT Kerberos web site: ... Network Identity Manager Kerberos v5 Support ...
    (comp.protocols.kerberos)
  • Re: cross-realm authentication problem
    ... Windows client are in KLIENT.UIB.NO, Windows user accounts are in UIB.NO, Unix/Linux machines and accounts are in UNIX.UIB.NO. ... I have one web server running RHEL4, apache 2.0.52 and Kerberos 1.3.4 as provided by Redhat, self-compiled mod_auth_kerb 5.4, and another running RHEL5, apache 2.2.3 and Kerberos 1.6.1 as provided by Redhat, self-compiled mod_auth_kerb 5.4. ... After authenticating against UIB.NO on a Linux machine (which have UNIX.UIB.NO as primary realm in krb5.conf) cross-realm authentication works fine. ... But using a Windows machine where the user is authenticated in UIB.NO I get cross-realm authentication only to the web server running RHEL4, not the one running RHEL5, I never even get a ticket for UNIX.UIB.NO from AD when trying to access the RHEL5 server web page. ...
    (comp.protocols.kerberos)
  • Re: 64bit Kerberos 5
    ... Second question, if there is not, what might the timeline be for providing 64bit support. ... Third question, are there any workarounds, or methods of forcing kerberos 5, to work in a 64bit environment.. ... If you are looking for MIT Kerberos for Windows, ...
    (comp.protocols.kerberos)