Article ID: 248808 - Last Review: October 30, 2006 - Revision: 1.1 Administrator Account Is Not Usable by Non-Windows 2000 Kerberos ClientsThis article was previously published under Q248808 SUMMARY
All Windows 2000 user accounts are also Kerberos principal names. This allows non-Windows-based implementations of Kerberos to use a Windows 2000 domain as a Kerberos realm. To enable this functionality, the equivalent DES-based key for use by interoperable implementations is stored whenever an account is created or a password is changed.
MORE INFORMATION
An account does not have a DES key in the following situations:
The Administrator account in a new domain also does not have an associated DES key. Clients that are not using Windows 2000 Kerberos cannot gain access to the account. When the password for the Administrator account is changed, all the associated keys are created. Clients that are not using Windows 2000 Kerberos can then gain access to the Administrator account. | Article Translations
|
Back to the top
