Re: Kerberos Security - How to switch off

From: Joshua Heslinga (jheslinga@attbi.com)
Date: 07/31/02


From: "Joshua Heslinga" <jheslinga@attbi.com>
Date: Tue, 30 Jul 2002 21:25:29 -0400


You can't disable Kerberos. It is the default authentication mechanism in
Windows 2000.

I haven't tried this, but since the key is that the client has the same time
as the server to which it's logging on:
    If you want a PC to be "in the future" / past / whatever and still able
to log in, put it and a domain controller on a separate network. Set both to
have the same time.

Joshua Heslinga

"Lee Steventon" <lsteventon@hotmail.com> wrote in message
news:29ce01c237b8$2003b820$19ef2ecf@tkmsftngxa01...
> Hi,
>
> We are trying to perform some "timeshift" testing in our
> organization which requires us to change the date and time
> on a local PC within an AD. This is necessary as we need
> to see the effects on customer accounts when the date is
> rolled forward (anywhere up to 10 years). When we roll
> back the date and attempt to log back on with the same
> domain account, we are locked out because of changes made
> to the Active Directory in "the future".
>
> Is this Kerberos locking us down because of the timestamp
> on the account and if so, how can we "disable" kerberos ?
>
> Kindest Regards



Relevant Pages

  • Re: impersonation using kerberos
    ... and then finding out you can enable kerberos event logging.... ... and for the computer account contains ... This error appears on my SQL box ... KDC cannot accommodate requested option. ...
    (microsoft.public.win2000.active_directory)
  • Re: Seamless/transparent SSO with Apache, Win2003, IE
    ... Did you have the 'Use DES encryption types for this account' option ticked ... I'm trying to create a seamless sign on to a web site ... using Solaris (Kerberos installed), Apache ... Sequence number: 315 (relative sequence number) ...
    (comp.protocols.kerberos)
  • Re: Howto refresh IIS 6 Application pool identity credential info
    ... I doubt the cluster environment has problems with kerberos tickets, ... Only account A has access to database DB-A ... Application A and Application B have an application security based on ... The Pool identity is the one accessing the backend resources like ...
    (microsoft.public.inetserver.iis.security)
  • RE: Excel Calculation Services
    ... \par Have you tried to use the Kerberos to delegate the credentials? ... If the sharepoint application pool is a domain account, then you must register an SPN for it, e.g. ... \par As for accessing data sources using delegation from excel services, ...
    (microsoft.public.sharepoint.portalserver.development)
  • Re: NTLM and Kerberos
    ... I would have to open port 88 to my Domain Controller? ... How would IE know which server is the Domain Controller (my home computer is ... Kerberos requires the user to obtain a Kerberos Service Ticket for the ... even attempt Kerberos authentication for sites in the Internet zone. ...
    (microsoft.public.inetserver.iis.security)