Click here to get back home

SPNEGO without a domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
SPNEGO without a domain Emily 02-21-2006
Posted by Emily on February 21, 2006, 4:21 pm
Please log in for more thread options
I tried posting this in the Access Security forum last week, but didn't hear
anything back, and thought maybe someone here would have some ideas? Thanks!

Hello,

Having a problem with Kerberos/SPNEGO authentication with a Windows XP
client. We have a non-Windows KDC and both Windows and non-windows clients.
On a unix-type machine, if I run kinit and authenticacate with the KDC, I
will get a TGT. Then, when I go to another intranet website that also
requires kerberos authentication, I am automagically given an HTTP ticket
(which I can see when I run klist) and allowed in the site. I want this same
functionality from winxp. I need this same functionality on a non-domained
windows client (and maybe domained ones as well, actually).

I've installed kerbtray which I think is whats given me the ability to do
the kinit/klist stuff on windows..

I really have no idea what to change. I've modified some firefox settings
to allow the browser to do spnego (setting
network.negotiate-auth.delegation-uris and
network.negotiate-auth.trusted-uris).

Does anyone know of a set specific instructions about this? If this is the
wrong forum for this type of question, also please let me know. Thanks :) :)
-- Emily

Posted by S. Pidgorny on February 22, 2006, 6:43 am
Please log in for more thread options
You have to use ksetup.exe from the support tools:

Using an MIT KDC with a Standalone Windows 2000 Workstation
(http://www.microsoft.com/technet/prodtechnol/windows2000serv/howto/kerbstep.mspx#EEAA)
- XP is similar


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-



>I tried posting this in the Access Security forum last week, but didn't
>hear
> anything back, and thought maybe someone here would have some ideas?
> Thanks!
>
> Hello,
>
> Having a problem with Kerberos/SPNEGO authentication with a Windows XP
> client. We have a non-Windows KDC and both Windows and non-windows
> clients.
> On a unix-type machine, if I run kinit and authenticacate with the KDC, I
> will get a TGT. Then, when I go to another intranet website that also
> requires kerberos authentication, I am automagically given an HTTP ticket
> (which I can see when I run klist) and allowed in the site. I want this
> same
> functionality from winxp. I need this same functionality on a non-domained
> windows client (and maybe domained ones as well, actually).
>
> I've installed kerbtray which I think is whats given me the ability to do
> the kinit/klist stuff on windows..
>
> I really have no idea what to change. I've modified some firefox settings
> to allow the browser to do spnego (setting
> network.negotiate-auth.delegation-uris and
> network.negotiate-auth.trusted-uris).
>
> Does anyone know of a set specific instructions about this? If this is the
> wrong forum for this type of question, also please let me know. Thanks :)
> :)
> -- Emily



Similar ThreadsPosted
SPNEGO / SSPI / SSO / GSSAPI Questions September 12, 2006, 11:11 am
How to create the SPNEGO token used in CIFS/SMB authentication? August 4, 2005, 4:42 pm
Event ID: 40960 SPNEGO (Negotiator) authentication error April 7, 2006, 3:22 am
Unable to resolve SPNEGO Event ID 40961 errors November 25, 2007, 12:54 pm
Allowing a Domain User Admin Rights to a Couple of Domain Servers June 29, 2005, 8:13 pm
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
domain access control for local user of domain computer? April 3, 2008, 5:14 pm
Cannot manage Entreprise CA that is in parent domain from child domain May 7, 2008, 4:03 am
ENTERPRISE DOMAIN CONTROLLERS Vs Domain Group Domain Controllers December 30, 2005, 3:08 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap