w2k kerberos logon

Luke Howard lukeh at PADL.COM
Fri Dec 13 16:28:23 EST 2002

>trying to get to understand how the kerberos client generates the domain
>name to authenticate the user when they enter the downlevel NetBIOS name in
>the logon dialog box.

The client simply uses the NetBIOS name as the realm, and sets the
canonicalize flag; the AS-REP contains the DNS domain name in the

-- Luke
Luke Howard | PADL Software Pty Ltd | www.padl.com

