How to Change Win 2000 Cached Account Password?

From: Some One (garg444NOSPAM_at_yahoo.com)
Date: 09/15/03


Date: Mon, 15 Sep 2003 05:58:27 GMT


I have two identical computers in two locations (W2K Pro).
They only have domain accounts (same id/password).
First PC has direct network connection. Second PC
is accessing network via VPN, cached credentials are used
to log in first.
There is rarely any need to access domain resources from the 2nd PC.
When domain password is periodically changed on the first computer
(due to security policy), I still have to log in to the 2nd PC
with an old password, and still can access network via VPN.
However, doing that locks the domain account out (apparently
either VPN software sends cached domain credentials / old domain
password to the network, or something else does that, even though
there is no need to use domain resources, and VPN still works
just fine with locked out account).

Is it possible to:
1. Update the domain password on the 2nd computer w/o physical connection
to domain (I suppose that'll be hard to do) or
2. If the credentials are stored in some specific files or registry
entries, where are these located. Can these files be copied to the
2nd PC to change password this way?
3. Anything else I can do to solve this problem (can't create
local account).

Thanks for any suggestions.



Relevant Pages

  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • TidBITS#792/15-Aug-05
    ... We also note the release of Security Update 2005-007, ... Macintosh FTP client, free for educational and charitable use. ... mentioned virtual private network (VPN) technologies. ...
    (comp.sys.mac.digest)
  • RE: VPN Error 800
    ... The VPN client IP is 10.0.1.40, this is a private IP address. ... server IP address is 81.137.105.244, this is a Internet IP address. ... not test VPN connection from your perimeter network. ... SBS on your switch to make it work. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN with SBS 2003 (not R2) and DSL.
    ... Reading property value for VPN returned OK ... Reading VPN Server Name returned OK ... identical network cards. ... it seems doubtful that SBS will work properly with two NICs ...
    (microsoft.public.windows.server.sbs)
  • Re: OT By a mile in parts comments on Viet Nam
    ... check bank accouts etc etc whilst away but is safe to do so over wireless and using the hotel network.. ... you should regard your connection as insecure and use some ... form of encryption to protect your passwords and privacy. ... My recommendation would be to set up a VPN endpoint in the UK that you ...
    (uk.comp.sys.mac)