Kerberos Authentication in Windows Server 2003

Technical Resources for IT Pros

Kerberos is an authentication mechanism used to verify user or host identity. This page contains the information you need to evaluate, plan, and deploy Kerberos, the preferred authentication method for services in Windows Server 2003. If you're new to Windows Server 2003, see the evaluation and introductory information about Kerberos authentication.

Introduction

What's New in Windows Server 2003 Kerberos Authentication

This page outlines the new features in Kerberos authentication and provides the basic information administrators need to begin using these features.

Planning and Architecture

Kerberos Protocol Transition and Constrained Delegation

This document examines ways to authenticate the users of Web applications and discusses how the new extensions to the Kerberos authentication protocol can satisfy these requirements.

Planning and Implementing Federated Forests in Windows Server 2003

This paper examines common scenarios where you can deploy Active DirectoryŽ forest trusts and describes the related technologies in Windows Server 2003.

Deployment

Server Clusters: Security Best Practices for Windows 2000 and Windows Server 2003

To ensure security in server cluster environments, organizations can implement these general assumptions and operational best practices for the infrastructure.

Kerberos Authentication for Load Balanced Web Sites

This document explains how to configure Kerberos in a way that enables applications to use its authentication capabilities in a cluster that also uses network load balancing.

Planning and Implementing Federated Forests in Windows Server 2003

This paper examines common scenarios where you can deploy Active DirectoryŽ forest trusts and describes the related technologies in Windows Server 2003.

Planning and Implementing Multitier Applications Using Windows Server 2003 Security Services

This white paper introduces Microsoft Windows Server 2003 security technologies and describes how they operate and interact with each other to allow you to build multitier applications that take advantage of these technologies to provide enhanced security.

Interoperability and Coexistence

Solution Guide for Windows Security and Directory Services for UNIX

This guide covers evaluating, planning, building, and deploying a security and directory infrastructure based on Windows Server 2003 using the Active Directory, Kerberos, and LDAP services.

Operations

Troubleshooting Kerberos Errors

This white paper helps you troubleshoot Kerberos authentication problems by outlining simple troubleshooting basics, explaining the causes of common Kerberos errors, and summarizing common troubleshooting tools.

Troubleshooting Kerberos Delegation

This white paper explains how to troubleshoot delegation issues that can arise in Kerberos authentication scenarios, summarizes required infrastructure, and describes Windows authentication scenarios.

Patch to Allow Referrals to Multiple Windows 2000 Domains

(On umich.edu) This is a modification of a patch written by Microsoft and obtained from MIT. This modification allows referrals to more than one W2K forest from a single MIT realm.

SPN Query

This script queries the Active Directory Global Catalog for a security principal with a specified service principal name (SPN).

Technical Reference

Kerberos Authentication Technical Reference

This reference explains what Kerberos authentication is and how the Kerberos version 5 protocol and extensions supported by Windows Server 2003 work.

Utilizing the Windows 2000 Authorization Data in Kerberos Tickets for Access Control to Resources

This document describes the structure of the Windows authorization data that is carried in that field for use by servers in performing access control. Information applies to Windows 2000 Server and Windows Server 2003.

IT Developer

Part I: Network Infrastructure—HTTP-Based Cross-Platform Authentication Via the Negotiate Protocol
Kerberos Protocol Transition and Constrained Delegation
Kerberos Protocol Transition and Constrained Delegation White Paper Samples
.NET Remoting Security Solution, Part 1: Microsoft.Samples.Security.SSPI Assembly
Planning and Implementing Multitier Applications Using Windows Server 2003 Security Services
Contoso Sample ASP.NET Extranet Application
Platform SDK: Security: SSPI
Server Clusters: Security Best Practices for Windows 2000 and Windows Server 2003
SSPI/Kerberos Interoperability with GSSAPI

Additional Resources

Vintela.com

Vintela Kerberos Management Package helps to maintain UNIX accounts in Windows.

SourceForge.net

Open Source SPNEGO module for Apache.

Columns

Professor Windows: Windows Server 2003 Trust Enhancements

Let Professor Windows guide you through trust relationships management in the Windows platform.

Tools

Windows Server 2003 Resource Kit Tools

Product Support

Knowledge Base Search

Webcasts

Introduction to Kerberos
Top of pageTop of page