Re: Smart Card Logon RODC



Hi.
I’ve got 2 sites. 1 with 2 DC and 1 with 1 RODC.
They have different V-lan and different subnets.
they replicate every hour.

/Johan

"Brian Komar (MVP)" wrote:

How are your sites defined in AD?
Brian

"jcarlen" <jcarlen@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:357C37A8-A023-48EB-83F5-6B1E270238E0@xxxxxxxxxxxxxxxx
Oki thank you, let me put it this way.
I have a lab with 3 DC 2 standrad and 1 RODC n diffrent sites.
When i logon to the RODC site with password it will authenticate against
the
RODC.
But when I logon with smart card it will authenticate aginst the primary
site. This becomes more clear when I simulate that the link goes down
between
the sites. I can still logon with password but with smart card it still
tries
to logon against the primary site and after the timeout then user will be
loged on locally on the client,
and not against the RODC.


"Brian Komar (MVP)" wrote:

No
"jcarlen" <jcarlen@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:11829C1A-3D80-4777-A415-29BC35F4C04C@xxxxxxxxxxxxxxxx
Hi.
When using smart cards against an RODC, is there anything I should do
to
diffrent from a normal smart card logon against a "Real" DC

Thanks
Johan




.



Relevant Pages

  • Re: Smart Card Logon RODC
    ... I have a lab with 3 DC 2 standrad and 1 RODC n diffrent sites. ... When i logon to the RODC site with password it will authenticate against the ... But when I logon with smart card it will authenticate aginst the primary ...
    (microsoft.public.windows.server.security)
  • Re: Smart Card Logon RODC
    ... I have a lab with 3 DC 2 standrad and 1 RODC n diffrent sites. ... When i logon to the RODC site with password it will authenticate against the ... But when I logon with smart card it will authenticate aginst the primary ...
    (microsoft.public.windows.server.security)
  • Re: RODC ...
    ... Win2003 DCs with RODC the WAN link between the RODC and RWDC goes ... Only then the users are able to logon if the WAN link is down. ... The Password Replication Policy acts as an access control list. ... The Password Replication Policy lists the accounts that are permitted ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... press CTRL + ALT + DEL to be able to log on with a different account. ...
    (microsoft.public.platformsdk.security)
  • Re: Problems loggin in Windows Vista with a smart card enabled acc
    ... account configured for smart card logon in Windows Vista. ... in the paper published by Microsoft that is titled 'Windows Vista Smart Card ... The provider may be returning a "no PIN prompt" flag and the SC ... The second tile says "other user" ...
    (microsoft.public.platformsdk.security)

Quantcast