Select the product you need help with
Error Message When Windows 95 or Windows NT 4.0 Client Logs On to Windows Server 2003 DomainArticle ID: 811497 - View products that this article applies to. On This PageSYMPTOMSWhen you log on to a Windows NT 4.0 computer that has
Service Pack 2 (SP2) or earlier installed, you may receive the following error
message: The system could not log you on. Make sure your
username and domain are correct, then type your password again. Letters in
passwords must be typed using the correct case. Make sure that Caps Lock is not
accidentally on. The domain password you supplied is not correct, or access to your
logon server has been denied. CAUSEBy default, security settings on domain controllers that run
Windows Server 2003 are configured to help prevent domain controller
communications from being intercepted or tampered with by malicious users. For
users to successfully negotiate communications with a domain controller that
runs Windows Server 2003, these default security settings require that client
computers use both server message block (SMB) signing and encryption or signing
of secure channel traffic. Clients that run Windows NT 4.0 with SP2 or earlier
installed and clients that run Windows 95 do not have SMB packet signing
enabled and cannot authenticate to a Windows Server 2003 domain controller.
RESOLUTIONWindows NT 4.0To resolve this behavior, upgrade the operating system (the recommended resolution), or install Service Pack 4 (SP4) or later. Service Pack 3 (SP3) provides support for SMB signing, but it does not support encryption or signing of secure channel traffic. Although SP4 and Service Pack 5 (SP5) do enable the client for SMB signing and encryption or signing of secure channel, Microsoft recommends that you install Service Pack 6a (SP6a) on Windows NT 4.0 clients that interoperate in a Windows Server 2003 domain.Windows 95To resolve this behavior, upgrade the operating system (the recommended resolution), or install the latest Active Directory client.WORKAROUND Although Microsoft does not recommend it, you can prevent
SMB signing from being required on all domain controllers that run Windows
Server 2003 in a domain. To configure this security setting, follow these
steps:
MORE INFORMATIONFor additional information about Active Directory client
extensions, visit the following Microsoft Web site: http://technet.microsoft.com/en-us/library/cc750223.aspx
(http://technet.microsoft.com/en-us/library/cc750223.aspx)
PropertiesArticle ID: 811497 - Last Review: December 3, 2007 - Revision: 9.6 APPLIES TO
| Article Translations |


Back to the top








