HP CIFS Windows 2000 Interoperability (October 2002)

CIFS/9000 and Windows 2000 Interoperability
Hewlett-Packard
21
4.3.2 Windows 2000 Client Logon with Kerberos: Mixed or Native
This is the Windows 2000 Pro client logon procedure. After finding the domain controller by
DNS lookup and establishing a secure connection with MSRPCs (Microsoft Remote
Procedure Calls), the client will request domain authentication. The first Kerberos exchange
provides the client with a ticket from the KDC. Next, the client requests a ticket for the
Domain Controller (DC$), and finally for the Kerberos service that is running on the KDC
(krbtgt).
Packets 50 and 51 show the Kerberos ticket exchange
Packets 52 and 53 show the DC$ domain controller service exchange
Packets 54 and 55 show the krbtgt service exchange
DNS QueryDNS Query
DNS ReplyDNS Reply
Request Secure ConnectionRequest Secure Connection
Secure Connection ReplySecure Connection Reply
W2000 Client
W2000 Server
CIFS/9000 Server
W2000 Client
W2000 Server
CIFS/9000 Server
Kerberos (TGT, TGS, Service)Kerberos (TGT, TGS, Service)
Kerberos RepliesKerberos Replies
TGT
TGS
Service