Click here to get back home

Kerberos logon to Terminal Server prevents folder redirection

 HomeNewsGroups | Search

get this group's latest topics as an RSS feed  microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late!

please rate
this thread
If you were  Registered and logged in, you could reply and use other advanced thread options
Posted by McDavid on May 29, 2009, 7:44 am
Client-to-WebInterface authentication = kerberos using passthrough.  This is
the authentication method that results in profile/FolderRedirecton failure
(since kerberos is not enabled on the file-share cluster).

When the users choose explicit logon at the Web Interface (which I believe
results in the Web Interface passing the users credentials to the XenApp
Server using NTLM), their profiles load just fine.

"Anthony [MVP]" wrote:



Posted by Anthony [MVP] on May 29, 2009, 1:36 pm
Pass-through refers to the client browser passing through credentials to the
Web Interface server; so you can still use Pass-through without enabling the
option "Use Kerberos authentication to connect to servers".
Likewise with the PNAgent you can enable Pass-through using the
single-signon service without enabling the option "Use Kerberos only".

I know there is a problem if you try to daisy-chain Citrix servers (i.e log
on to Web Interface, connect to a published desktop on a Citrix server, and
from there connect to a published app on another Citrix server).

"Pass-through authentication is not available when accessing a published
application from within a published desktop on XenApp 5.0 servers. Instead,
the user must provide valid credentials to launch a session within a desktop
session even when pass-through authentication is enabled in the plugin. To
resolve this issue, you must install a server-side hotfix that contains Fix
#194894. [#194894]"

So it looks to me as though you either need to enable Kerberos on the
cluster; or disable Kerberos options in the Pass-through,
Anthony
http://www.airdesk.com





Posted by McDavid on May 29, 2009, 2:51 pm
Originally the README had said that single sign-on was not available from a
published desktop unless you used kerberos.  So, we configured our Web
Interface site to use kerberos (as opposed to spinning off and managing
another site that doesn't use kerberos... one for the clients and one for the
XenApp desktop).

I didn't realize they had published a hotfix for this issue.  Might resolve
our issue if cranking up kerberos on the file shares doesn't work.

"Anthony [MVP]" wrote:



Posted by Anthony [MVP] on May 30, 2009, 5:50 am
OK, good luck. It sounds as thought there isn't any reason for the cluster
not to use Kerberos anyway,
Anthony,
http://www.airdesk.com





Subject Author Date
Kerberos logon to Terminal Server prevents folder redirection McDavid 05-26-2009
If you were  Registered and logged in, you could reply and use other advanced thread options

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

1-Script XML SitemapXML Sitemap
Privacy Policy