Domain Authentication when DC downed?

From: David Jones (kk7gw@yahoo.com)
Date: 11/11/02


From: "David Jones" <kk7gw@yahoo.com>
Date: Sun, 10 Nov 2002 18:34:22 -0800


Well, it somewhat depends.

In general, I don't believe so, as the XP machine needs
to authenticate the network user with the DC.

It's possible that if the domain is a Windows 2000 domain
that uses Kerberos, the ticket(s) in use might still be
valid and there would be no need to talk to the DC.

As a general rule, network authentication of domain
accounts requires a DC actively responding though.

>-----Original Message-----
>Dear all,
>
>We know that WinXP will cache the domain user password
when a domain user
>logon the machine, so that even the machine cannot
connect to any DC it can
>still let the user logon the machine. How about a
share's authentication?
>
>If the WinXP Pro machine cannot connect to any DCs and
the same network has
>a domain user "Alice" connect to this WinXP Pro
machine's share "PUBLIC"
>which is open for the domain user "Alice" only, will she
able to connect to
>the share?
>
>
>Thanks,
>Charles
>
>
>
>.
>



Relevant Pages

  • Re: Application Pool with domain user identity doesnt work with anonymous access disbled
    ... you want to use a fixed identity to connect to the network share (in ... Use Kerberos authentication and delegation. ... and use Protocol Transition (requires Windows 2003 Server Domain + Windows ... > application domain running a domain user as Identity. ...
    (microsoft.public.inetserver.iis.security)
  • Network account lockout
    ... I have a laptop running a personal copy of WinXP Pro. ... resources that require authentication my network account ... gets locked (MS domain type network). ...
    (microsoft.public.windowsxp.network_web)
  • Application Pool + Domain User + Windows authentication - bug?
    ... This works fine on Windows 2000, but on Windows Server 2003 ... the Windows Authentication is going to crazy after the lot of page ... Create Application Pool for this application with domain user ...
    (microsoft.public.inetserver.iis)
  • Re: Logon to domain account takes long in windows server 2003
    ... There could be some network device that is blocking some of the kerberos UDP packets. ... On any client machine it takes long for a domain user to log on to a domain user account. ... I have already checked if lots of data is being transferred between the server and the client during logon to a domain account but barely any data is being transferred between the two machines during that process. ...
    (microsoft.public.win2000.active_directory)
  • Browsing Network
    ... I have a W2K domain and I'm logging into it from a W2K Pro workstation with ... Domain User account. ... When I click on my network places and then search the Entire Network / ... SYSVOL folders ...
    (microsoft.public.windows.server.general)

Quantcast