Windows Domain login step



Hi,
I tryed to understand the steps involved in a windows domain login,
from the machine startup to the desktop loading.
I read a lot of articles and I try to synthetize the procedure as
follow:
1) turn on the computer
2) Machine authentication with, for example, EAP-TLS. This step
involve the computer (supplicant), an authenticator (i.e. the Access
point if we are in a WiFi environment or a switch if we are in a wired
environment) and a RADIUS Server (IAS in Windows Domain)
3) Once the machine is authenticated, the machine starts a DHCP
request to obtain an IP address. The DHCP Server reply and the
computer obtain his IP address
4) The GINA is displayed and the user prompt in his username and
password
5) User authentication with, for example EAP-MSCHAP v2. This step
involve the computer (supplicant), an authenticator (i.e. the Access
point if we are in a WiFi environment or a switch if we are in a wired
environment) and a RADIUS Server (IAS in Windows Domain)
6) Once the user is authenticated he can request a domain service,
like a printer.
7) A Kerberos session begins. The client send to Domain Controller
(where reside KDC (Key Distribution Center) and TGS (Ticket Granting
Service)) a request to obtain the ticket for the Printer Server.
8) At the end of Kerberos session, the deskotp is loaded.

Is that procedure correct? Can someone help me to understand the
correct order?
Thanks (and sorry for my english)!!!

Paolo

.



Relevant Pages

  • Re: Radius Authentication
    ... Confirm that authentication against the RADIUS server succeeds using ... Windows domain account (if the name contains spaces then refer to the ...
    (freebsd-questions)
  • Re: How can a linux machine login one WinNT Domain?
    ... >> asking if you can use a Windows domain for login authentication on the ... > I am not clear about the http proxy authentication. ... If you wan't to logon to windows domain from Linux box use smbpasswd utility ... If you wan't to enable samba server to authenticate windows machines like ads ...
    (comp.os.linux.networking)
  • How to get UserName / NetBios machine name using FORMS authentication
    ... I'm using Forms authentication but I still need to know the NetBios ... machine name and the user logged on on windows domain, ... browser IE to access my ASP.NET application. ... the software on witch workstation width witch ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Windows Authentication question
    ... We are creating an intranet here in ASP.NET and we decided that we are ... going to use a kind of Forms Authentication but using the users in our ... windows domain. ... So, we are creating a default login form, but the user will use the name ...
    (microsoft.public.dotnet.security)
  • Windows Authentication question
    ... We are creating an intranet here in ASP.NET and we decided that we are ... going to use a kind of Forms Authentication but using the users in our ... windows domain. ... So, we are creating a default login form, but the user will use the name ...
    (microsoft.public.dotnet.framework)