Kerberos Ticket User

From: Will (DELETE_westes_at_earthbroadcast.com)
Date: 04/27/05


Date: Tue, 26 Apr 2005 23:15:26 -0700

In our Active Directory server user list, I see a user account for the
Kerberos ticket service, but it is marked as disabled. The Kerberos ticket
service is running with SYSTEM authority. Is this the default
configuration?

If you want to use the Kerberos use account to run the Kerberos ticket
service, are you supposed to change the password, or does Kerberos maintain
and change this password on its own? What steps are required to make this
secure?

We need to run Kerberos ticket as a user so that it will be able to pass
Kerberos tickets through a winsock proxy that only allows specific user
accounts to pass through.

-- 
Will


Relevant Pages

  • Re: Kerberos Ticket User
    ... The krbtgt account is disabled by default and the system manages the ... You do not nor should not reconfigure that account. ... > Kerberos ticket service, but it is marked as disabled. ...
    (microsoft.public.windows.server.security)
  • Re: Expired Account
    ... ability to access the resource ends when the Kerberos ticket expires. ... neither a user who is locked out nor a computer account can renew ...
    (microsoft.public.windows.server.active_directory)
  • KDC error at logon !
    ... I have upgraded a NT4 PDC to W2K in mixte mode. ... type:error " The account FRED has not a valid key to ... generate a Kerberos ticket." ...
    (microsoft.public.win2000.security)