Mapping users in KSETUP vs. Active Directory

Andrew Riley ariley at isc.upenn.edu
Fri May 9 17:58:56 EDT 2003


On a windows 2000 server running active directory, we are
doing pass-thru
authentication to an MIT KDC.

when users are mapped in active directory they can log in
fine using their
kerberos principal, either locally on the server or at a
workstation.  but if
the user is mapped using KSETUP.EXE it only works locally on
the server.  not at a
workstation attached to the domain.  any ideas?

The thing i'm trying to do is have it map all kerberos
principals to a single account on the domain controller.  I
can't figure out how to do that in AD.  in KSETUP it just
lets you use a wildcard.

thanks
andrew




More information about the Kerberos mailing list