Click here to get back home

Kerberos Ticket Renewal Problem with SC Logon

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Kerberos Ticket Renewal Problem with SC Logon Chipeater 05-30-2006
Posted by Chipeater on May 30, 2006, 7:05 am
Please log in for more thread options
Hi,
I'm experiencing problems whereby users (who've logged on with smart
cards) leave their machines logged on overnight. On unlocking their
workstations in the morning users get a message in their system tray
telling them that Windows needs their current credentials and a green
Kerberos icon in the systray. The users try to renew their credentials
as instructed by locking / unlocking their workstation, but alas no
success. The users cannot shutdown gracefully as their connections to
their network shares are dropped which stops them saving their profile.

I think this is due to the Kerberos user ticket expiring after the
default 10 hours? Shouldn't Kerberos re-authenticate silently in the
background after unlocking the workstation in the morning. I know that
the users should log off, but they don't and this cannot be changed!

Any ideas?


Posted by Steven L Umbach on June 3, 2006, 6:22 pm
Please log in for more thread options
Configure the Local Security Policy [or via domain policy] to automatically
logoff the user when their smart card is removed under local
policies/security options - interactive logon: smart card removal behavior.
That should solve your problem. If their still is a problem that means they
are leaving their smart cards in the smart card reader which in my opinion
would be a gross security violation which defeats much of the advantage of
using smart cards and should not be allowed via computer user policy. ---
Steve


show/hide quoted text



Posted by Raji Arulambalam on June 8, 2006, 1:40 am
Please log in for more thread options
Hi

Is there a way to increase their end time to 24 hrs instead of the default
10 hours?
I have tried setting this in the Domain Security Policy for Kerberos Policy
( Max lifetime for service and user ticket), but the clients (Windows XP
SP2) shows that the lifetime is 10 hours. (used kerbtray and klist to get
this)
Windows 2003 servers.

Is there an article that gives what the valid range of time that can be set
for the kerberos tickets instead of the defaults.?

Thanks
RajiA

show/hide quoted text



Posted by Chipeater on June 8, 2006, 9:57 am
Please log in for more thread options
Steven,
Thanks for the advice... unfortunately forced logoff cannot be
employed.

Raji,
Here are a couple of useful articles which might help you...
http://www.microsoft.com/technet/security/prodtech/windows2000/w2kccadm/acctpol/w2kadm09.mspx
http://support.microsoft.com/?kbid=323931


Similar ThreadsPosted
Kerberos Ticket Renewal Problem June 8, 2006, 1:48 am
Kerberos Ticket Granting Ticket Registry Key Entry September 6, 2006, 9:20 am
Kerberos Error Getting Ticket From Domain: krb5kdc_err_s_principal_unknown June 23, 2006, 3:34 am
Windows Server 2003 PKI CA certificate renewal problem November 18, 2009, 2:14 am
Kerberos logon to Terminal Server prevents folder redirection May 26, 2009, 1:28 pm
wireless logon to domain problem January 9, 2007, 2:04 pm
Computer certificate renewal December 12, 2008, 11:12 am
Smartcard Auto-Renewal March 4, 2009, 5:26 pm
Use restrictec accounts instead of Admin accounts. Problem with runas and deny logon locally June 24, 2009, 11:17 am
Re: Subordinate CA server renewal with an online CA root server July 17, 2008, 8:48 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy