I am in the process of putting in an Active Directory 2003 domain. Currently I have an NT4.0 domain which operates a 2-way trust to the AD domain. Our RAS server is a windows 2000 server which also has IAS radius running on it.
Before I started mass moving users onto the new domain I thought i...
looks like i have run out of time for this, my company has now dictated that we remain with our current method of authentication onto unix boxes by using the security = server option and not joining the unix boxes to the AD domain. Hopefully if we leave it a few more months there might be a bit...
yes we have an active wins service running on the domain controller and Bernie is set to point to this machine for WINS lookups as in the statement you have suggested.
hmmm, that's a problem, we don't own a copy of SMS, i have read a few articles that said microsoft released a kerberos parser dll for netmon with windows 2003 resource kit but i have installed the kit and it makes no reference to a kerberos parser dll at all and even the microsoft support...
i have these in the security log which correspond to the time the trace was taken from.
Authentication Ticket Request:
User Name: bernie$
Supplied Realm Name: IM-SERV.COM
User ID: IM-SERV\bernie$
Service Name: krbtgt
Service ID: IM-SERV\krbtgt
Ticket Options: 0x50000010...
my fault, i must have filtered too much traffic, there is return packets as seen below
Network Monitor trace Thu 01/15/04 22:09:49 bernie.txt
*************************************************************************************************************************
Frame Time Src MAC Addr...
dam, i have not installed the monitoring tools of the win2k3 cd and as i am at home i cannot put the cd into the servers cdrom drive. I'll do it first thing tomorrow morning!
i'm trying to connect to the unix box from the kdc as my AD domain only consist of the domain controllers and 2 unix boxes so do i just need to run one trace on the kdc?
the administrator account has not been used to join the unix box to the domain, i created another account for this unix box which is a member of the account operators group which has permissions to join a machine to the domain.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.