Re: Heimdal KDC, Windows XP and local users



Javier Palacios wrote:
I have configured Windows XP to use a Heimdal KDC for user authentication.
All existing Windows users can authenticate against the KDC, user
mapping is "ksetup /mapuser * *".

However, Windows does not create a new local user with the same name
as the Kerberos princical I try to authenticate as.

If you have users defined on LDAP, maybe the s+c Authentication
Package (http://sourceforge.net/projects/sc-ap/) might help you. And
if your valid users are not available anywhere, it is not hard to
modify to drop the LDAP lookups and simply create a local account.

Thank you for the link, however LDAP seems superfluous for my purpose.
The goal was to maintain the user database in just one place, and
Kerberos + LDAP mean two places.

--
Victor Sudakov, VAS4-RIPE, VAS47-RIPN
2:5005/49@fidonet http://vas.tomsk.ru/
.



Relevant Pages

  • Re: Heimdal KDC, Windows XP and local users
    ... All existing Windows users can authenticate against the KDC, ... Windows does not create a new local user with the same name ... modify to drop the LDAP lookups and simply create a local account. ...
    (comp.protocols.kerberos)
  • Re: access denied - IS THERE a definitive solution????
    ... accounts were added while part of the domain... ... none of the local user ... The part that's really ticking off, though, is that I DO authenticate ... profile created. ...
    (microsoft.public.win32.programmer.wmi)
  • Re: access denied - IS THERE a definitive solution????
    ... none of the local user ... The part that's really ticking off, though, is that I DO authenticate ... profile created. ... I would test deleting the profile created for the user when in a workgroup, ...
    (microsoft.public.win32.programmer.wmi)
  • Re: ADAM Question: Windows users cannot login unless they are member of local admins
    ... Windows users can bind to ADAM as long as the user represents a security principal trusted by the ADAM server (a local user or a domain user from a trusted domain). ...
    (microsoft.public.windows.server.active_directory)
  • Re: Client Certificate not reaching server
    ... Clould you please elobarate. ... > authenticate the local user, not the server, so the private key is needed. ... >> am adding that certificate file to httpwebrequest. ...
    (microsoft.public.dotnet.security)