Networking Forums

Networking Forums > Computer Networking > Windows Networking > Kerberos to NTLM???

Reply
Thread Tools Display Modes

Kerberos to NTLM???

 
 
Spin
Guest
Posts: n/a

 
      11-08-2004, 06:00 PM
Someone did a sniffer trace bettween Windows 2000 servers and Windows 2000
domain controllers on our network and found at that many of our Windows 2000
servers are attempting to communicate using Kerberos to the DCs, not
negotiating for whatever reason, then falling back to NTLM. Does anyone
know why this might be happening?


 
Reply With Quote
 
 
 
 
Roland Hall
Guest
Posts: n/a

 
      11-08-2004, 06:10 PM
"Spin" wrote in message news:(E-Mail Removed)...
: Someone did a sniffer trace bettween Windows 2000 servers and Windows 2000
: domain controllers on our network and found at that many of our Windows
2000
: servers are attempting to communicate using Kerberos to the DCs, not
: negotiating for whatever reason, then falling back to NTLM. Does anyone
: know why this might be happening?
:
Are they in native mode?

--
Roland Hall
/* This information is distributed in the hope that it will be useful, but
without any warranty; without even the implied warranty of merchantability
or fitness for a particular purpose. */
Online Support for IT Professionals -
http://support.microsoft.com/service...p?fr=0&sd=tech
How-to: Windows 2000 DNS:
http://support.microsoft.com/default...b;EN-US;308201
FAQ W2K/2K3 DNS:
http://support.microsoft.com/default...b;EN-US;291382


 
Reply With Quote
 
Spin
Guest
Posts: n/a

 
      11-09-2004, 05:25 PM
Yes.

"Roland Hall" <nobody@nowhere> wrote in message
news:#(E-Mail Removed)...
> "Spin" wrote in message news:(E-Mail Removed)...
> : Someone did a sniffer trace bettween Windows 2000 servers and Windows

2000
> : domain controllers on our network and found at that many of our Windows
> 2000
> : servers are attempting to communicate using Kerberos to the DCs, not
> : negotiating for whatever reason, then falling back to NTLM. Does anyone
> : know why this might be happening?
> :
> Are they in native mode?
>
> --
> Roland Hall
> /* This information is distributed in the hope that it will be useful, but
> without any warranty; without even the implied warranty of merchantability
> or fitness for a particular purpose. */
> Online Support for IT Professionals -
> http://support.microsoft.com/service...p?fr=0&sd=tech
> How-to: Windows 2000 DNS:
> http://support.microsoft.com/default...b;EN-US;308201
> FAQ W2K/2K3 DNS:
> http://support.microsoft.com/default...b;EN-US;291382
>
>



 
Reply With Quote
 
Roland Hall
Guest
Posts: n/a

 
      11-11-2004, 08:51 PM
: "Roland Hall" <nobody@nowhere> wrote in message
: news:#(E-Mail Removed)...
: > "Spin" wrote in message news:(E-Mail Removed)...
: > : Someone did a sniffer trace bettween Windows 2000 servers and Windows
: 2000
: > : domain controllers on our network and found at that many of our
Windows
: > 2000
: > : servers are attempting to communicate using Kerberos to the DCs, not
: > : negotiating for whatever reason, then falling back to NTLM. Does
anyone
: > : know why this might be happening?
: > :
: > Are they in native mode?


"Spin" wrote in message news:(E-Mail Removed)...
: Yes.

It is by design if Kerberos authentication fails, NTML authentication is
then attempted.
http://www.microsoft.com/resources/d...f_upg_lgrl.asp

Perhaps this offers some insight as to why this is happening:
Full article:
http://www.windowsecurity.com/articl...ntrollers.html

Excerpt:
Windows 2000 and 2003 domain controllers support Kerberos and NTLM
authentication protocols. When a Windows 2000 or later computer needs to
find out if a domain account is authentic the computer first tries to
contact the DC via Kerberos. If it doesn't receive a reply it falls back to
NTLM. In an AD forest comprising computers running Windows 2000 and later
all authentication between workstations and servers should be Kerberos.
Windows 2000 and later domain controllers log different event IDs for
Kerberos and NTLM authentication activity so it's easy to distinguish them.
In an AD forest of Windows 2000 or later computers, any NTLM authentication
events you see on domain controllers can only have a few explanations.
First, Windows will fall back to NTLM if routers for some reason block
Kerberos traffic (UDP port 88). Second, if your domain trusts another domain
outside your forest (defined in Active Directory Domains and Trusts) you'll
see NTLM events on you domain controllers since Kerberos doesn't work for
external trust relationships. (Note: Windows Server 2003 supports a new type
of trust call cross forest trusts. A cross forest trust is a transitive,
2-way trust between 2 Windows Server 2003 domains. Cross forest trusts use
Kerberos - not NTLM.) The third explanation for NTLM events on your domain
controller's security log are rogue computers. Contrary to popular
misconception, Windows does not prevent a user at a computer from an
un-trusted domain or stand-alone computer (Windows computer that doesn't
belong to any domain) from connecting to a server in your domain using a
domain account. To prove this just map a drive to a computer in an
untrusting domain using the "net use" command. For instance in the below
example I connect to a file server called NYC-FS-1 in the NYC domain using
the domain Administrator account and a password of #dk32HE4.

--
Roland Hall
/* This information is distributed in the hope that it will be useful, but
without any warranty; without even the implied warranty of merchantability
or fitness for a particular purpose. */
Online Support for IT Professionals -
http://support.microsoft.com/service...p?fr=0&sd=tech
How-to: Windows 2000 DNS:
http://support.microsoft.com/default...b;EN-US;308201
FAQ W2K/2K3 DNS:
http://support.microsoft.com/default...b;EN-US;291382


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
NTLM Authentication. jay_kbvt Linux Networking 0 02-16-2007 11:52 AM
Is a Kerberos realm in UNIX is analogous to a Kerberos AD domain? Spin Windows Networking 3 12-06-2005 04:33 AM
Kerberos realm in UNIX is analogous to a Kerberos AD domain? Spin Windows Networking 0 12-02-2005 11:49 PM
Kerberos back to NTLM Spin Windows Networking 3 11-14-2004 01:13 AM
FTP and Kerberos - Kerberos V4 krb_mk_req !! karthik bala guru Linux Networking 1 08-04-2004 05:15 PM



1 2 3 4 5 6 7 8 9 10 11