Solved

Which version of Kerberos do I use?

Posted on 2011-03-04
7
883 Views
Last Modified: 2012-05-11
Hi,

We are using a single-sign on software from Evidian.
We've noticed that on our Windows 7 x86 machines, the user is not automatically identified by Evidian when logging in with firstname.lastname@domain.com". The user then have to retype his password in the Evidian window.

On ther other hand, when logging in with the short username, the Evidian engine recognises the account and automatically identifies the user.

I believe this is due to the way Kerberos is used.

I've read years ago the differences between logging in with  "firstname.lastname@domain.com" or the short username, but I do not find the information back on the Net.

Could someone refresh my memory and let me know what are the difference for Kerberos between the long and short username?

I've already found this (http://technet.microsoft.com/en-us/library/cc772815%28WS.10%29.aspx) but it doesn't say whether using the short or long username make a difference or not

Thanks
0
Comment
Question by:CCBelux
  • 4
  • 3
7 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35041933
What is first.last@domain.com is that their email address or rehire UPN?
0
 

Author Comment

by:CCBelux
ID: 35056958
Hi demazter, this is indeed the UPN (and also the email address).
So when logging in with the logon name it doesn't work, when loggin in with the pre-)Windows 2000  logon name, it does work.
07-Mar-2011-15-23-52.jpg
0
 
LVL 74

Accepted Solution

by:
Glen Knight earned 500 total points
ID: 35057008
There is no difference in the way kerberos works (as far as I am aware) when you use the different login styles.  Just some software is not written to recognise the UPN's and therefore will not work.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:CCBelux
ID: 35057612
OK, I thought using the "post-Windows 2000" logon forced the usage of kerberos v5 while the "pre-Windows 2000" logon still used an older version. Do you confirm ?
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35057640
Not that I am aware of.  It's not something I've ever heard of to be honest.
0
 

Author Comment

by:CCBelux
ID: 35057685
OK, I'll accept your comment as answer then. if anyone has any other info, please add your comment.

Thanks demazter
0
 

Author Closing Comment

by:CCBelux
ID: 35057698
Accepted until someone else prooves otherwise
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have been working as System Administrators since 2003. I recently started working as a FreeLancer and was amazed to find out that very few people are taking full advantage of their Windows Server Machines. Microsoft Windows Server comes with so…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question