Advertisement

02.28.2007 at 10:28AM PST, ID: 22419430
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

4.2

Domain Members authenticate with NTLM instead of Kerberos

Asked by scopeortho in Microsoft Server, Windows 2003 Server, Active Directory

Tags: ,

I have been looking at several threads in this forum and many others.  But I am clueless on how to proceed with my problem.  I have a windows 2003 Native domain with two DC's.  On my default domain controller policy I have disabled SMB Microsoft Network Server (digitally sign communications always).  But I do have Microsoft Network Server (Digtially sign communications if client agrees) Enabled.  I also have "Network Security Lan Manager authentication level: Send LM & NTLM - use NTLMv2 session security if negotiated" enabled.  This is because I have windows 98 clients and DOS 6.2 clients on my network. Now on my default domain policy I have enabled Send NTLMv2 response only and refuse LM & NTLM and Digitally sign communication always.  This is just for NTLM and SMB signing, I know that!  Windows 2K and above the default authentication package is Kerberos.  Basically my problem is that I am seeing windows xp, windows 2000, and windows 2003 servers authenticating via NTLM and not Kerberos.  I have done some Network Monitoring and kerberos logging, I get the following in kerberos error:

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      3
Date:            2/27/2007
Time:            3:35:16 PM
User:            N/A
Computer:      %Computer Name%
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 23:35:16.0000 2/27/2007 Z
 Error Code: 0xd KDC_ERR_BADOPTION
 Extended Error: 0xc00000bb KLIN(0)
 Client Realm:
 Client Name:
 Server Realm: SCOPE.LOCAL
 Server Name: host/%server%
 Target Name: host/%server%
 Error Text:
 File: 9
 Line: ae0
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 30 15 a1 03 02 01 03 a2   0.¡....¢
0008: 0e 04 0c bb 00 00 c0 00   ...»..À.
0010: 00 00 00 03 00 00 00      .......

I get this error on both domain controlllers.  So I am thinking that I have a kerberos problem that is causing some of the members in the domain to authenticate via NTLM.  I do not see any Kerberos traffic in Network Monitor.  When a client reboots the last thing I see before several SMB packets is the LDAP request from the client looking for Netlogon service.  I thought the problem could be the time service in my domain so I verified that I am not recieving time errors durning these authentication times.  I l also have a login in script to set the time with the PDC Emulator.  Like I said it happens to some clients and member servers.  This what I see on both domain controllers:

Logon attempt by:      MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 Logon account: %user%
 Source Workstation:      %Computer Name%
 Error Code:      0x0

On one domain controller that as doubles up as a file server I see these:
Event Type:      Success Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      540
Date:            2/28/2007
Time:            10:17:55 AM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      DC1
Description:
Successful Network Logon:
       User Name:      
       Domain:            
       Logon ID:            (0x0,0x37E6B2E)
       Logon Type:      3
       Logon Process:      NtLmSsp
       Authentication Package:      NTLM
       Workstation Name:      %Computer Name%
       Logon GUID:      -
       Caller User Name:      -
       Caller Domain:      -
       Caller Logon ID:      -
       Caller Process ID: -
       Transited Services: -
       Source Network Address:      %IP Address%
       Source Port:      0


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Both DC's are W2K3 with SP1.  I ran Kerbtray on the DC's and on some of these clients that authenticate with NTLM and they are getting ST and TGT's.  What can be the problem and how do I make my W2K and above clients authenticate only via kerberos.  The kerberos GPO is following for the defualt domain policy:

Enforce user logon restrictions Enabled
Maximum lifetime for service ticket 720 minutes
Maximum lifetime for user ticket 12 hours
Maximum lifetime for user ticket renewal 7 days
Maximum tolerance for computer clock synchronization 5 minutes

For the Default Domain Controller policy is the following:

Maximum tolerance for computer clock synchronization 5 minutes

Dennis
Start Free Trial
[+][-]02.28.2007 at 01:55PM PST, ID: 18629287

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.28.2007 at 03:08PM PST, ID: 18629842

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]02.28.2007 at 04:08PM PST, ID: 18630156

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.01.2007 at 05:17AM PST, ID: 18632581

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.01.2007 at 05:18AM PST, ID: 18632584

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.01.2007 at 08:28AM PST, ID: 18633597

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.02.2007 at 06:45AM PST, ID: 18641053

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.02.2007 at 07:13AM PST, ID: 18641336

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:24AM PST, ID: 18672479

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:36AM PST, ID: 18672593

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:37AM PST, ID: 18672604

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:38AM PST, ID: 18672612

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:46AM PST, ID: 18672705

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:52AM PST, ID: 18672761

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 10:58AM PST, ID: 18672817

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 11:45AM PST, ID: 18673187

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 11:52AM PST, ID: 18673253

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 01:24PM PST, ID: 18674097

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.07.2007 at 01:33PM PST, ID: 18674188

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.12.2007 at 07:32AM PDT, ID: 18702266

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.12.2007 at 10:26PM PDT, ID: 18707794

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.13.2007 at 10:29AM PDT, ID: 18712234

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.13.2007 at 12:05PM PDT, ID: 18712997

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.13.2007 at 12:19PM PDT, ID: 18713114

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 12:07AM PDT, ID: 18716593

View this solution now by starting your 14-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Microsoft Server, Windows 2003 Server, Active Directory
Tags: kerberos, ntlm
Sign Up Now!
Solution Provided By: chakote
Participating Experts: 3
Solution Grade: A
 
 
[+][-]03.14.2007 at 07:42AM PDT, ID: 18718760

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 09:11AM PDT, ID: 18719616

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 09:13AM PDT, ID: 18719638

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 10:27AM PDT, ID: 18720373

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 12:45PM PDT, ID: 18721570

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 12:48PM PDT, ID: 18721605

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.14.2007 at 04:02PM PDT, ID: 18722961

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.15.2007 at 08:30AM PDT, ID: 18727749

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.15.2007 at 11:19AM PDT, ID: 18729188

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 14-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]03.15.2007 at 11:39AM PDT, ID: 18729359

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20081112-EE-VQP-43