1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Kerberos logon to Terminal Server prevents folder redirection.

Discussion in 'Windows Security' started by McDavid, May 22, 2009.

  1. McDavid

    McDavid Guest

    Environment:
    - Windows 2008 x64 Server Standard
    - Kerberos Token Size set to maximum

    Issue:
    When our users logon to our Terminal Servers using kerberos, they receive a
    temporary profile and none of the Folder Redirection policies are applied.
    The event log reports both processing failing with "Logon failure: unknown
    user name or bad password.". However the user is successfully logged onto
    the server using kerberos. The server hosting the profiles also reports
    "unknown user name or bad password" in the security log and the
    authentication package as NTLM. The users can navigate to the network
    locations of their roaming profiles and redirected folders just fine without
    any errors.

    If the users logon to our Terminal Servers using NTLM, their roaming profile
    is loaded and folder redirection policies applied successfully.

    Kerberos is the required authentication method for logging into our Terminal
    Servers. We are using Citrix Web Interface and single signon leverages
    kerberos.
     
  2. McDavid

    McDavid Guest

    I turned on Kerberos logging on the Terminal Server. When the user logs into
    the Terminal Server using kerberos, the logon process attempts to load their
    profile and redirect their profiles using kerberos. This is failing because
    we don't have SPNs registered for these resources. I'm guessing the logon
    process then attempts NTLM and that is failing because they didn't login with
    NTLM.

    Is there any way to get the fallback to NTLM to function? If not, how does
    one go about registering SPNs for file-shares that are cluster resources
    (virtual IPs and computer names that aren't regisered in Active Directory).
    In addition, how does one go about registering SPNs for DFS roots?

    Any/all help is appreciated.

    Thanks.

    "McDavid" wrote:
    <!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Environment:
    > - Windows 2008 x64 Server Standard
    > - Kerberos Token Size set to maximum
    >
    > Issue:
    > When our users logon to our Terminal Servers using kerberos, they receive a
    > temporary profile and none of the Folder Redirection policies are applied.
    > The event log reports both processing failing with "Logon failure: unknown
    > user name or bad password.". However the user is successfully logged onto
    > the server using kerberos. The server hosting the profiles also reports
    > "unknown user name or bad password" in the security log and the
    > authentication package as NTLM. The users can navigate to the network
    > locations of their roaming profiles and redirected folders just fine without
    > any errors.
    >
    > If the users logon to our Terminal Servers using NTLM, their roaming profile
    > is loaded and folder redirection policies applied successfully.
    >
    > Kerberos is the required authentication method for logging into our Terminal
    > Servers. We are using Citrix Web Interface and single signon leverages
    > kerberos.<!--colorc--><!--/colorc-->
     
  3. Peter Foldes

    Peter Foldes Guest

    McDavid

    You will be better off by posting this to a Server related Security newsgroup

    On the web:



    --
    Peter

    Please Reply to Newsgroup for the benefit of others
    Requests for assistance by email can not and will not be acknowledged.

    "McDavid" <McDavid@discussions.microsoft.com> wrote in message
    news:300A9A9C-E283-46F0-A363-5AA51FB0AA29@microsoft.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    >I turned on Kerberos logging on the Terminal Server. When the user logs into
    > the Terminal Server using kerberos, the logon process attempts to load their
    > profile and redirect their profiles using kerberos. This is failing because
    > we don't have SPNs registered for these resources. I'm guessing the logon
    > process then attempts NTLM and that is failing because they didn't login with
    > NTLM.
    >
    > Is there any way to get the fallback to NTLM to function? If not, how does
    > one go about registering SPNs for file-shares that are cluster resources
    > (virtual IPs and computer names that aren't regisered in Active Directory).
    > In addition, how does one go about registering SPNs for DFS roots?
    >
    > Any/all help is appreciated.
    >
    > Thanks.
    >
    > "McDavid" wrote:
    ><!--coloro:green--><span style="color:green <!--/coloro-->
    >> Environment:
    >> - Windows 2008 x64 Server Standard
    >> - Kerberos Token Size set to maximum
    >>
    >> Issue:
    >> When our users logon to our Terminal Servers using kerberos, they receive a
    >> temporary profile and none of the Folder Redirection policies are applied.
    >> The event log reports both processing failing with "Logon failure: unknown
    >> user name or bad password.". However the user is successfully logged onto
    >> the server using kerberos. The server hosting the profiles also reports
    >> "unknown user name or bad password" in the security log and the
    >> authentication package as NTLM. The users can navigate to the network
    >> locations of their roaming profiles and redirected folders just fine without
    >> any errors.
    >>
    >> If the users logon to our Terminal Servers using NTLM, their roaming profile
    >> is loaded and folder redirection policies applied successfully.
    >>
    >> Kerberos is the required authentication method for logging into our Terminal
    >> Servers. We are using Citrix Web Interface and single signon leverages
    >> kerberos. <!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     

Share This Page