Starting 70-640 training, a few questions.
1. identities subject kerberos authentification (users, groups, etc)?
2. domains part of server, vice versa, or it's own separate entity?
3. can identities denied kerberos authentification?
4. identities subject kerberos authentification , username/password protocol? can these set by administrator turned on/off?
5. can individual documents/applications issued access control list?
that's comes mind @ moment. appreciate input.
time.
hi,
1. kerberos default authentication method in ad domain.
2. domain not part of server. domains container objects. domains collection of administratively defined objects share common directory database, security policies, , trust relationships other domains. in way, each domain administrative boundary objects. single domain can span multiple physical locations or sites , can contain millions of objects.
3. yes, can denied.
note:
although kerberos protocol authenticates user's identity, not authorize access. kerberos ticket proves user user claims be. after user’s identity verified, local security authority authorize or deny resource access.
4. windows operating system supports several protocols verifying identities of users claim have accounts on system. may disable kerberos authentication turning off kdc service on dc.
5. the access control list, or acl, used specify list of individual access control entries (aces). can configure acl on individual file/folder.
additionally, here articles related ad domain , kerberos authentication may understand more clearly:
what kerberos authentication?
http://technet.microsoft.com/en-us/library/cc780469.aspx
what domains , forests?
Windows Server > Windows Server General Forum
Comments
Post a Comment