Click here to get back home

Kerberos logon to Terminal Server prevents folder redirection

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Kerberos logon to Terminal Server prevents folder redirection McDavid 05-26-2009
Posted by McDavid on May 29, 2009, 7:44 am
Please log in for more thread options
Client-to-WebInterface authentication = kerberos using passthrough. This is
the authentication method that results in profile/FolderRedirecton failure
(since kerberos is not enabled on the file-share cluster).

When the users choose explicit logon at the Web Interface (which I believe
results in the Web Interface passing the users credentials to the XenApp
Server using NTLM), their profiles load just fine.

"Anthony [MVP]" wrote:

show/hide quoted text

Posted by Anthony [MVP] on May 29, 2009, 1:36 pm
Please log in for more thread options
Pass-through refers to the client browser passing through credentials to the
Web Interface server; so you can still use Pass-through without enabling the
option "Use Kerberos authentication to connect to servers".
Likewise with the PNAgent you can enable Pass-through using the
single-signon service without enabling the option "Use Kerberos only".

I know there is a problem if you try to daisy-chain Citrix servers (i.e log
on to Web Interface, connect to a published desktop on a Citrix server, and
from there connect to a published app on another Citrix server).

"Pass-through authentication is not available when accessing a published
application from within a published desktop on XenApp 5.0 servers. Instead,
the user must provide valid credentials to launch a session within a desktop
session even when pass-through authentication is enabled in the plugin. To
resolve this issue, you must install a server-side hotfix that contains Fix
#194894. [#194894]"

So it looks to me as though you either need to enable Kerberos on the
cluster; or disable Kerberos options in the Pass-through,
Anthony
http://www.airdesk.com



show/hide quoted text

Posted by McDavid on May 29, 2009, 2:51 pm
Please log in for more thread options
Originally the README had said that single sign-on was not available from a
published desktop unless you used kerberos. So, we configured our Web
Interface site to use kerberos (as opposed to spinning off and managing
another site that doesn't use kerberos... one for the clients and one for the
XenApp desktop).

I didn't realize they had published a hotfix for this issue. Might resolve
our issue if cranking up kerberos on the file shares doesn't work.

"Anthony [MVP]" wrote:

show/hide quoted text

Posted by Anthony [MVP] on May 30, 2009, 5:50 am
Please log in for more thread options
OK, good luck. It sounds as thought there isn't any reason for the cluster
not to use Kerberos anyway,
Anthony,
http://www.airdesk.com


show/hide quoted text

Similar ThreadsPosted
Folder redirection September 15, 2008, 3:28 am
Folder redirection and security November 9, 2005, 10:45 am
audit logon/logoff events on terminal server July 18, 2007, 10:29 am
Logon/Logoff Events in Local Security Log of Terminal Server July 20, 2007, 2:39 pm
Logon Using Terminal Services GPO August 16, 2007, 2:57 am
Deny Logon through Terminal Services Issue August 22, 2006, 12:49 pm
Kerberos Ticket Renewal Problem with SC Logon May 30, 2006, 7:05 am
win2k3 ent with sp2 : configure terminal server to use TLS for server authentication is not work!! June 2, 2009, 7:56 am
USER AND TERMINAL SERVER July 3, 2007, 7:12 am
Locking down Terminal Server May 5, 2009, 1:54 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy