Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Administration > Vista compatibility with mixed system kerberos authentication?

Reply
Thread Tools Display Modes

Vista compatibility with mixed system kerberos authentication?

 
 
tkmlee
Guest
Posts: n/a

 
      01-26-2007
Does Vista support single sign on kerberos authentication with a unix kds?

With our current infrastructure, we use ksetup in our Windows 2003 AD with
XP clients to add the kerberos realm for our users to login.

So far, with some breif testing, the same group policy that we use on our XP
machines (ksetup to add the kerberos realm), doesn't work on Vista. Is there
a version of ksetup or similar that is used in Vista?

Thanks!
 
Reply With Quote
 
 
 
 
tkmlee
Guest
Posts: n/a

 
      02-27-2007
anyone?

"tkmlee" wrote:

> Does Vista support single sign on kerberos authentication with a unix kds?
>
> With our current infrastructure, we use ksetup in our Windows 2003 AD with
> XP clients to add the kerberos realm for our users to login.
>
> So far, with some breif testing, the same group policy that we use on our XP
> machines (ksetup to add the kerberos realm), doesn't work on Vista. Is there
> a version of ksetup or similar that is used in Vista?
>
> Thanks!

 
Reply With Quote
 
Jason
Guest
Posts: n/a

 
      03-28-2007
Admittedly, I'm don't know a great deal about this but am trying to
learn more....how are you using group policy to leverage ksetup to add
the kerberos realm? I know in my work environment we have a GPO that
runs a .reg file with the /s switch that adds the necessary registry
entry for our kerberos realm. HKEY_LOCAL_MACHINE\SYSTEM
\CurrentControlSet\Control\Lsa\Kerberos\Domains\{d omain name}
with a value of KdcNames:REG_MULTI_SZ:{kdc server}

This .reg entry works for the Vista clients as well. No ksetup.exe
necessary. But we have another problem. It seems when users lock their
Vista screens all their tickets are destroyed and then not renewed
when the they re-authenticate to unlock the screen. That's not
helpful!


tkmlee wrote:
> anyone?
>
> "tkmlee" wrote:
>
> > Does Vista support single sign on kerberos authentication with a unix kds?
> >
> > With our current infrastructure, we use ksetup in our Windows 2003 AD with
> > XP clients to add the kerberos realm for our users to login.
> >
> > So far, with some breif testing, the same group policy that we use on our XP
> > machines (ksetup to add the kerberos realm), doesn't work on Vista. Is there
> > a version of ksetup or similar that is used in Vista?
> >
> > Thanks!


 
Reply With Quote
 
tkmlee
Guest
Posts: n/a

 
      05-25-2007
same here if its a laptop without a network connection, the credentials don't
cache and the user can't log into the kerberos realm.... not a good thing.....

"Jason" wrote:

> Admittedly, I'm don't know a great deal about this but am trying to
> learn more....how are you using group policy to leverage ksetup to add
> the kerberos realm? I know in my work environment we have a GPO that
> runs a .reg file with the /s switch that adds the necessary registry
> entry for our kerberos realm. HKEY_LOCAL_MACHINE\SYSTEM
> \CurrentControlSet\Control\Lsa\Kerberos\Domains\{d omain name}
> with a value of KdcNames:REG_MULTI_SZ:{kdc server}
>
> This .reg entry works for the Vista clients as well. No ksetup.exe
> necessary. But we have another problem. It seems when users lock their
> Vista screens all their tickets are destroyed and then not renewed
> when the they re-authenticate to unlock the screen. That's not
> helpful!
>
>
> tkmlee wrote:
> > anyone?
> >
> > "tkmlee" wrote:
> >
> > > Does Vista support single sign on kerberos authentication with a unix kds?
> > >
> > > With our current infrastructure, we use ksetup in our Windows 2003 AD with
> > > XP clients to add the kerberos realm for our users to login.
> > >
> > > So far, with some breif testing, the same group policy that we use on our XP
> > > machines (ksetup to add the kerberos realm), doesn't work on Vista. Is there
> > > a version of ksetup or similar that is used in Vista?
> > >
> > > Thanks!

>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to initialize the security package Kerberos for server side authentication Willy Windows Vista Networking 0 02-18-2008 11:36 PM
Kerberos authentication support in Windows Mail WaveRaider Windows Vista Mail 9 11-14-2007 08:06 PM
Mixed SCSI, IDE -- system partition and page file(s) saltbeet Windows Vista Installation 3 11-09-2007 09:36 PM
Vista kerberos realm login tkmlee Windows Vista Security 0 02-27-2007 11:31 PM
Kerberos error from Vista workstations Dan Lepine Windows Vista Security 0 07-21-2006 08:35 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59