Click here to get back home

Security log entries

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security log entries r. wales 05-05-2006
Posted by r. wales on May 5, 2006, 12:16 pm
Please log in for more thread options
I recieved these two event entries. What exactly are they telling me? (ie.
ticket options, ecryption type, pre-authentication type, etc). I haven't had
much luck getting piece by piece explanations anywhere on the internet. I
have a DC running win 2k3 with xp pro clients. Thanks for your help.

Event Type:        Success Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        672
Date:                5/5/2006
Time:                2:47:11 AM
User:                NT AUTHORITY\SYSTEM
Computer:        <Servername domain controller, win 2k3>
Description:
Authentication Ticket Request:
        User Name:                <username>
        Supplied Realm Name:        <DomainName>.LOCAL
        User ID:                        <Domain User>
        Service Name:                krbtgt
        Service ID:                <DomainName>\krbtgt
        Ticket Options:                0x40810010
        Result Code:                -
        Ticket Encryption Type:        0x17
        Pre-Authentication Type:        2
        Client Address:                <ipaddress>
        Certificate Issuer Name:        
        Certificate Serial Number:        
        Certificate Thumbprint:        


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Event Type:        Success Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        673
Date:                5/5/2006
Time:                2:47:11 AM
User:                NT AUTHORITY\SYSTEM
Computer:        <Servername domain controller, win 2k3>
Description:
Service Ticket Request:
        User Domain:                <DomainName>.LOCAL
        Service Name:                krbtgt
        Service ID:                <DomainName>\krbtgt
        Ticket Options:                0x60810010
        Ticket Encryption Type:        0x17
        Client Address:                <ipaddress>
        Failure Code:                -
        Logon GUID:                
        Transited Services:        -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Posted by bagins on May 7, 2006, 3:57 am
Please log in for more thread options

Kerberos authentication technical reference
http://technet2.microsoft.com/WindowsServer/en/Library/b748fb3f-dbf0-4b01-9b22-be14a8b4ae101033.mspx

Kerberos authentication in W2K3
http://www.microsoft.com/windowsserver2003/technologies/security/kerberos/default.mspx

W2K3 Kerberos extensions
http://technet2.microsoft.com/WindowsServer/en/Library/4c8b5ac7-368b-45b9-91d7-1ae7c5e0da311033.mspx

Google
http://www.google.com/search?q=kerberos+windows+2003+site:microsoft.com


************************
Best regards
Bagins
************************


>I recieved these two event entries. What exactly are they telling me?
>(ie.
> ticket options, ecryption type, pre-authentication type, etc). I haven't
> had
> much luck getting piece by piece explanations anywhere on the internet. I
> have a DC running win 2k3 with xp pro clients. Thanks for your help.
>
> Event Type: Success Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 672
> Date: 5/5/2006
> Time: 2:47:11 AM
> User: NT AUTHORITY\SYSTEM
> Computer: <Servername domain controller, win 2k3>
> Description:
> Authentication Ticket Request:
> User Name: <username>
> Supplied Realm Name: <DomainName>.LOCAL
> User ID: <Domain User>
> Service Name: krbtgt
> Service ID: <DomainName>\krbtgt
> Ticket Options: 0x40810010
> Result Code: -
> Ticket Encryption Type: 0x17
> Pre-Authentication Type: 2
> Client Address: <ipaddress>
> Certificate Issuer Name:
> Certificate Serial Number:
> Certificate Thumbprint:
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
>
>
> Event Type: Success Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 673
> Date: 5/5/2006
> Time: 2:47:11 AM
> User: NT AUTHORITY\SYSTEM
> Computer: <Servername domain controller, win 2k3>
> Description:
> Service Ticket Request:
> User Domain: <DomainName>.LOCAL
> Service Name: krbtgt
> Service ID: <DomainName>\krbtgt
> Ticket Options: 0x60810010
> Ticket Encryption Type: 0x17
> Client Address: <ipaddress>
> Failure Code: -
> Logon GUID:
> Transited Services: -
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>



Similar ThreadsPosted
Firewall Log Entries Help May 31, 2006, 4:15 pm
Win2003 Server - 10,000 Entries ! February 9, 2006, 11:28 pm
Adding multiple entries for the same user with xcacls... July 19, 2007, 2:21 pm
How to automatically inherit permission entries on child objects? January 21, 2006, 7:43 am
Domain Local Security vs Global Security vs Universal Security Groups October 16, 2006, 1:26 pm
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 8:00 am
Windows Server Baseline Security - IE security warning June 5, 2007, 9:35 am
security in AD June 22, 2005, 5:38 am
VPN Security. July 19, 2005, 9:44 am
Security? July 25, 2005, 8:56 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap