Go to the Penn State Home page

Go to the CLC Home page

Go to the ITS Home page
This site uses .Net links. Please use Text Only version for screen readers.  Text Only Printable Version    Secure Server Search CLC:   
   
  CLC Home
  News
  Labs
  Classrooms
  Assistive Technology
  Printing
  Disk Space
  Authentication
  Mobile Ports
  Verify Password
  Lab Admin Support
  Contacts
  About Us
  Search

Domain win.psu.edu Authentication Changes

Summary

ASET removed the password change synchronization from www.work.psu.edu to the win.psu.edu domain on August 15, 2006.  The win.psu.edu domain now uses the MIT Kerberos servers in the dce.psu.edu realm and a "cross-realm trust" for password authentication.   Users logging onto computers in the win.psu.edu tree who were using accounts in win.psu.edu have to log into the dce.psu.edu Kerberos realm instead of win.psu.edu.  Shadow accounts will still be maintained in win.psu.edu and Kerberos name mappings have been set to enable this.  After logging in users have credentials for both win.psu.edu and dce.psu.edu, so this may be viewed as an expanded service.  ACLs on file servers for principals in win.psu.edu do not have to be changed, but any service relying on NTLM and not Kerberos no longer works.

Schedule

Details

Logging onto a computer in the win.psu.edu forest using the dce.psu.edu Kerberos realm results in credentials for win.psu.edu, as long as there is no name mapping for a matching user account the child domain. In other words, do not set Kerberos name mappings for accounts in the child domain (such as staff.win.psu.edu).

The registry settings set by the "DceKDCs.msi" are in the key SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\dce.psu.edu.  

The RealmFlags value is a REG_DWORD 8.  A multreg value named KdcNames previously documented here is no longer needed.

You can find a reg file in this zip file.

For the labs.win.psu.edu domain we will also deploy an MSI that sets/resets the default login domain to dce.psu.edu so that if someone picks win the next person will see dce.psu.edu.  We'll discuss if that should be linked for the staff domain or OU's in the staff domain.

Testing

Password de-sync, re-sync

Testing with your win.psu.edu password synchronized with your dce.psu.edu is not indicative of what will work or not.   Windows will often use cached passwords from other domains when attempting to access resources. You might first try logging into dce.psu.edu without changing your win.psu.edu password to see if everything works the same way, but then you should change the win.psu.edu password and try again.

Go to https://clc.its.psu.edu/DomPassChange.aspx to change your win.psu.edu domain password to something else, then test logging onto dce.psu.edu with your Access Account password, NOT the one you just set.

If you forget what your new win.psu.edu password is, you can go to https://clc.its.psu.edu/SetWinPass.aspx to set it back to the same as your dce.psu.edu password. We may have to keep this utility after August 1 in case of unforeseen problems (it has been removed).

Verify both passwords at https://clc.its.psu.edu/users/VerifyPassword.aspx.  This page will also tell you if you win.psu.edu account is locked.

What To Test, Staff

The goal is that everything should look the same and work the same when logging on with dce.psu.edu\<userid> instead of win.psu.edu\<userid>.  If the account has been used in CLC labs and the profile set to roaming on the workstation, you may even see the U: and V: drives connected automatically.

You can connect to a share like \\dc1.aset.psu.edu\sysvol to see if you have credentials for it.  You should not be prompted for a userid and password when logged into dce.psu.edu.

What To Test, Labs

Lab consultants can test on (selected?) consultant machines:

Wireless

Computers with wireless-only connections may be a problem.  Need to test.

Profiles

Roaming profiles seem ok.  However, if you get an error message with an event log description like "Cross Forest roaming user profiles are disabled. Windows did not load your roaming profile and is logging you on with a local profile. Changes to the profile will not be copied to the server when you logoff. Contact your network administrator." you have to enable the policy "Allow Cross-Forest User Policy and Roaming User Profiles", found under Administrative Templates, System/Group Policy.  (Shouldn't this be set domain-wide?  Checking.)

Local profiles should be tested (same or different?)

Informational Tools

The Windows Resource Kit has a klist.exe that will list your current Kerberos tickets, and a krbtray.exe that will put an icon in the notification area that you can click on to open a window to list Kerberos tickets.  You may have to be a power user or administrator for those to work.  To add an account to the local administrators group, you would add win\<userid>, not dce.psu.edu\<userid>.

Problems

Send new problem reports to admin@staff.win.psu.edu.

Known Problems

Assuming the WIN account password is not the same as the dce.psu.edu Kerberos password, there these known problems:

Unknowns Problems

Management requests a list of all unknown problems.  Please forward your unknown problems up your management chain.

Solved Problems

 


© 2006, The Pennsylvania State University. All rights reserved.
This site maintained by the Classroom and Lab Computing group of Information Technology Services.
Suggestions and comments about this web site: CLC Webmasters; Other contacts here.

This page was last modified: 1/23/2007 9:11:59 AM.