Re: Kerberos Ticket User
From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 04/27/05
- Next message: Will: "Re: Kerberos Ticket User"
- Previous message: Craig n: "Need help with NTAP32SMS.EXE Virus- ASAP - Mission Critical"
- In reply to: Will: "Re: Kerberos Ticket User"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 27 Apr 2005 11:07:13 -0400
Strictly speaking, any kerberized computer in an AD domain has a user account,
it is the machine account of the computer. This means you can ACL resources for
specific machines. The LocalSystem and NetworkService well known security
principals use the computer credentials when accessing remote resources.
For instance, if I wanted the LocalSystem/NetworkService on one DC to be able to
access a file share on a computer, I can add the machine account for that DC to
the ACL on that file share and then anything running under those two contexts
could access that file share.
Not sure if the proxy server is smart enough to work with this but if you are
simply setting an ACL and the proxy is on a machine that is part of the forest,
it *may* work.
-- Joe Richards Microsoft MVP Windows Server Directory Services www.joeware.net Will wrote: > If you are not familiar with Microsoft Proxy Server 2.0, it has a > mode where only domain accounts can get through the proxy. > SYSTEM accounts are always forbidden from getting through the > proxy. > > I need kerberos tickets to pass out through the proxy. The only > way I can think to make that happen is for the Kerberos ticket > service to run as a domain account. > > Is there any way to run the Kerberos ticket server under the > permissions of a specific domain user, or did Microsoft hack it > in such a way that it must always run as SYSTEM? > > What is the purpose of the krbtgt account if it is always > disabled? >
- Next message: Will: "Re: Kerberos Ticket User"
- Previous message: Craig n: "Need help with NTAP32SMS.EXE Virus- ASAP - Mission Critical"
- In reply to: Will: "Re: Kerberos Ticket User"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|