NT machine accounts

From: Andy (andy_at_debo.com.nosp)
Date: 10/30/03


Date: Wed, 29 Oct 2003 23:17:45 GMT

Hopefully quite easy this one...

Every machine in a domain needs to have a machine account on the PDC.
The name of this account is the machine name with a $ afterwards.
Easy. Like MYSERVER$. But this account has a password...

1. It seems like the password gets issued initially FROM the PDC to
the client i.e. when the machine joins the domain it says 'whats my
password?'. Is this right?

2. Every so often, default 7 days in NT, the machine gets another
password. But is this 'refresh' password generated by the machine and
passed to the PDC or does again the PDC hand the password down to the
machine (after a request from the machine)?

3. The initial password seems to be the machine name. OK. But what
about the subsequent ones i.e. those that get generated every week?

4. How come when I do a lophtcrack on my SAM/registry a lot of the
machine account passwords are blank?

5. Regardless of what end generates the machine account password, how
does it securely tell the other end what password has been generated?

6. What length is the password that is generated? Is it random or
fixed in some way?

Well, OK, it's maybe not that easy to answer after all!! But if
anyone can help it would be great.

Andy



Relevant Pages

  • Re: Samba Shares & Windows 2000
    ... I need to set up a machine account on the Linux box in order for ... > the Win2k box to join the domain. ... I don't use Samba as my PDC so I haven't tried it but check out this ...
    (alt.os.linux.suse)
  • Re: Master Browser related questions
    ... In NT 4.0 the PDC contains the only modifiable copy of the ... domain wide changes e.g., new computers, password change, ... BTW it's not just the machine account. ... > Thank You for the useful information! ...
    (microsoft.public.windows.server.networking)
  • Re: Master Browser related questions
    ... > domain wide changes e.g., new computers, password change, ... > hidden machine account password changes. ... > resolve the 1b name to find the PDC of the domain. ... >> Thank You for the useful information! ...
    (microsoft.public.windows.server.networking)