我正在使用kerberos来验证用户及其失败。事件查看器中的审核失败详细信息如下:
A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: ax
Supplied Realm Name: TEST.COM
User ID: NULL SID
Service Information:
Service Name: krbtgt/TEST.COM
Service ID: NULL SID
Network Information:
Client Address: ::ffff:2.2.2.60
Client Port: 38532
Additional Information:
Ticket Options: 0x40800000
Result Code: 0x6
Ticket Encryption Type: 0xffffffff
Pre-Authentication Type: -
Certificate Information:
Certificate Issuer Name:
Certificate Serial Number:
Certificate Thumbprint:
Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
结果代码0x6表示用户不存在于Kerberos数据库中,但我已经在AD中配置了用户。 这是Windows Server 2008(非R2),用户帐户名是" axtest"用户登录名是" ax / mytest"。域名是test.com。从wireshark,我可以看到我的客户端正在发送AS-REQ,它具有正确的2个名称字符串项ax& mytest的。我不知道为什么会失败。
答案 0 :(得分:1)
我发现了问题。由于我运行的是旧的Microsoft 2008版本,因此缺少此修补程序(KB951191)。安装解决了这个问题。