HP CIFS Windows 2000 Interoperability (October 2002)
CIFS/9000 and Windows 2000 Interoperability
Hewlett-Packard
21
4.3.2 Windows 2000 Client Logon with Kerberos: Mixed or Native
This is the Windows 2000 Pro client logon procedure. After finding the domain controller by
DNS lookup and establishing a secure connection with MSRPCs (Microsoft Remote
Procedure Calls), the client will request domain authentication. The first Kerberos exchange
provides the client with a ticket from the KDC. Next, the client requests a ticket for the
Domain Controller (DC$), and finally for the Kerberos service that is running on the KDC
(krbtgt).
• Packets 50 and 51 show the Kerberos ticket exchange
• Packets 52 and 53 show the DC$ domain controller service exchange
• Packets 54 and 55 show the krbtgt service exchange
DNS QueryDNS Query
DNS ReplyDNS Reply
Request Secure ConnectionRequest Secure Connection
Secure Connection ReplySecure Connection Reply
W2000 Client
W2000 Server
CIFS/9000 Server
W2000 Client
W2000 Server
CIFS/9000 Server
Kerberos (TGT, TGS, Service)Kerberos (TGT, TGS, Service)
Kerberos RepliesKerberos Replies
TGT
TGS
Service