Click here to get back home

Local caching of passwords

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Local caching of passwords Keith 07-29-2005
Posted by Keith on July 29, 2005, 12:14 pm
Please log in for more thread options
Where is the user's password cached when you have a GPO setting on
Interactive logon: Number of previous logons to cache (in case domain
controller is not available)? Is it store in LSASS secrets?

If we set our server to not store local cache of user's password what
application or other things will break? I u nderstand that if you turn that
off and there is no domain controller available that you will be unable to
logon to that server in that domain...But what other hidden gotchas are out
there that I might not be thinking of?



Posted by Miha Pihler [MVP] on July 30, 2005, 11:58 am
Please log in for more thread options
Hi Keith,

The cached credentials are stored in Registry under HKLM\Security\Cache. To
actually see the Cache Key you will have to change permissions on Security
part of the registry (give Administrator appropriate permissions).

After you change the policy for cached credentials from 10 to e.g. 0 you
will see NL$1 to NL$10 disappear.

--
Mike
Microsoft MVP - Windows Security

> Where is the user's password cached when you have a GPO setting on
> Interactive logon: Number of previous logons to cache (in case domain
> controller is not available)? Is it store in LSASS secrets?
>
> If we set our server to not store local cache of user's password what
> application or other things will break? I u nderstand that if you turn
> that
> off and there is no domain controller available that you will be unable to
> logon to that server in that domain...But what other hidden gotchas are
> out
> there that I might not be thinking of?
>




Similar ThreadsPosted
Product to Automatically Change Local Passwords? August 31, 2006, 4:07 am
Server caching credentials? July 6, 2007, 4:08 pm
strong passwords October 6, 2005, 11:02 am
Exporting Passwords January 15, 2006, 3:20 pm
Question on passwords June 9, 2006, 3:07 pm
Computer Passwords September 14, 2006, 9:32 am
Can I have two passwords for one user? June 6, 2007, 7:50 pm
RE: Lost passwords November 2, 2007, 2:31 pm
Audit AD passwords December 4, 2007, 9:53 am
Safe Keeping passwords July 6, 2005, 9:53 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap