BOINC and Domain Controller

Message boards : Number crunching : BOINC and Domain Controller
Message board moderation

To post messages, you must log in.

Previous · 1 · 2 · 3 · Next

AuthorMessage
Matthew S. McCleary
Avatar

Send message
Joined: 9 Sep 99
Posts: 121
Credit: 2,288,242
RAC: 0
United States
Message 966254 - Posted: 28 Jan 2010, 2:11:18 UTC - in response to Message 966203.  

@ozzfan
Hi
What is wrong advice about active directory.
Just want to know.
If I understand right ntlmv2 is default on win 7 and ntlm is used default on win 2000 and 2003. How do I enable ntlm and ntlmv2 on my win 7 laptop.
Or should I de enable ntlm on my win 2000 or enable ntlmv2 on my win 2000.
A lot of people are having trouble see shares from their server from win 7 including linux servers.

Paul


Active Directory uses the NTLM protocol to authenticate computer or user accounts, with NTLM being used on older versions of Windows and Windows Server, and NTLMv2 being used in Server 2008/Vista/7.


Nope. Active Directory uses DNS to resolve names and Kerberos to authenticate computer and user objects.
ID: 966254 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966268 - Posted: 28 Jan 2010, 3:05:09 UTC - in response to Message 966254.  

Active Directory .... Kerberos to authenticate computer and user objects.

Spot on Flain, plus including kerberos aware apps, assuming all parties are in a AD domain model (and kerb rhelm), ideally Native Mode, as mixed mode still has an emulated PDC w/NTLM auth services. But keep in mind there is still SPNEGO to negotiate downwards and/or across the river.

Most of the cross model SMB sharing access problems I've seen in recent years are resolved by knowing how to set up a session and passing through a valid set of credentials (between two computers that agree on the current TIME).

PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD.
ID: 966268 · Report as offensive
Profile HAL9000
Volunteer tester
Avatar

Send message
Joined: 11 Sep 99
Posts: 6534
Credit: 196,805,888
RAC: 57
United States
Message 966270 - Posted: 28 Jan 2010, 3:12:48 UTC - in response to Message 966268.  

Active Directory .... Kerberos to authenticate computer and user objects.

Spot on Flain, plus including kerberos aware apps, assuming all parties are in a AD domain model (and kerb rhelm), ideally Native Mode, as mixed mode still has an emulated PDC w/NTLM auth services. But keep in mind there is still SPNEGO to negotiate downwards and/or across the river.

Most of the cross model SMB sharing access problems I've seen in recent years are resolved by knowing how to set up a session and passing through a valid set of credentials (between two computers that agree on the current TIME).

PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD.

Yeah they should really be using WFW 3.12.
SETI@home classic workunits: 93,865 CPU time: 863,447 hours
Join the [url=http://tinyurl.com/8y46zvu]BP6/VP6 User Group[
ID: 966270 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966271 - Posted: 28 Jan 2010, 3:14:23 UTC - in response to Message 966270.  

Right on, Hal, and we all know WFW hasn't been the same since Andre the Giant passed away :(
ID: 966271 · Report as offensive
Profile Pappa
Volunteer tester
Avatar

Send message
Joined: 9 Jan 00
Posts: 2562
Credit: 12,301,681
RAC: 0
United States
Message 966273 - Posted: 28 Jan 2010, 3:19:08 UTC - in response to Message 966181.  

@ozzfan
Hi
What is wrong advice about active directory.
Just want to know.
If I understand right ntlmv2 is default on win 7 and ntlm is used default on win 2000 and 2003. How do I enable ntlm and ntlmv2 on my win 7 laptop.
Or should I de enable ntlm on my win 2000 or enable ntlmv2 on my win 2000.
A lot of people are having trouble see shares from their server from win 7 including linux servers.

Paul


The simple reason is, it adds a layer of "complexity" that did not solve your problem (or others).

So while the discussion has drifted away...........

Regards

Please consider a Donation to the Seti Project.

ID: 966273 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15692
Credit: 84,761,841
RAC: 28
United States
Message 966275 - Posted: 28 Jan 2010, 3:24:12 UTC - in response to Message 966254.  

@ozzfan
Hi
What is wrong advice about active directory.
Just want to know.
If I understand right ntlmv2 is default on win 7 and ntlm is used default on win 2000 and 2003. How do I enable ntlm and ntlmv2 on my win 7 laptop.
Or should I de enable ntlm on my win 2000 or enable ntlmv2 on my win 2000.
A lot of people are having trouble see shares from their server from win 7 including linux servers.

Paul


Active Directory uses the NTLM protocol to authenticate computer or user accounts, with NTLM being used on older versions of Windows and Windows Server, and NTLMv2 being used in Server 2008/Vista/7.


Nope. Active Directory uses DNS to resolve names and Kerberos to authenticate computer and user objects.


I don't recall saying anywhere about resolving names. Kerberos is used to authenticate, along with NTLM depending on what services are installed.
ID: 966275 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15692
Credit: 84,761,841
RAC: 28
United States
Message 966283 - Posted: 28 Jan 2010, 3:32:36 UTC - in response to Message 966268.  
Last modified: 28 Jan 2010, 3:36:21 UTC

PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD.


I'll take that as a direct comment to me since I'm the only one in this thread having admitted to running WfW 3.11 - perhaps you should consider what motives I may have before suggesting that I turn it off. Further, AD is not needed on every Windows network. I never said that it shouldn't be considered, I stated that it wasn't the best solution for PaulDHarris's situation if he's only running one server, or more specifically, against previous advice that was given to him as mentioned in his message earlier in the thread:

...I got my win 7 laptop I could not open any shares on my server because of ntlmv2 in win 7 and pre win 7 uses ntlm and so win 7 does not see the earlier server shares. I was told to install active directory which is domain controller and now I can see my shares on my win 7 laptop but BOINC won't install on my server because it is now a domain controller...


It wasn't necessary to install AD to access his shares, or to even see them for that matter.

Perhaps those of you with a little knowledge of the situation could offer better advice instead of trying to play this game of one-upsmanship that is so often rift on these boards with techies.
ID: 966283 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15692
Credit: 84,761,841
RAC: 28
United States
Message 966284 - Posted: 28 Jan 2010, 3:34:06 UTC - in response to Message 966273.  
Last modified: 28 Jan 2010, 3:47:22 UTC

@ozzfan
Hi
What is wrong advice about active directory.
Just want to know.
If I understand right ntlmv2 is default on win 7 and ntlm is used default on win 2000 and 2003. How do I enable ntlm and ntlmv2 on my win 7 laptop.
Or should I de enable ntlm on my win 2000 or enable ntlmv2 on my win 2000.
A lot of people are having trouble see shares from their server from win 7 including linux servers.

Paul


The simple reason is, it adds a layer of "complexity" that did not solve your problem (or others).

So while the discussion has drifted away...........

Regards


Thank you Al. That's exactly what I was getting at.
ID: 966284 · Report as offensive
1mp0£173
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 8423
Credit: 356,897
RAC: 0
United States
Message 966285 - Posted: 28 Jan 2010, 3:35:46 UTC - in response to Message 966275.  

@ozzfan
Hi
What is wrong advice about active directory.
Just want to know.
If I understand right ntlmv2 is default on win 7 and ntlm is used default on win 2000 and 2003. How do I enable ntlm and ntlmv2 on my win 7 laptop.
Or should I de enable ntlm on my win 2000 or enable ntlmv2 on my win 2000.
A lot of people are having trouble see shares from their server from win 7 including linux servers.

Paul


Active Directory uses the NTLM protocol to authenticate computer or user accounts, with NTLM being used on older versions of Windows and Windows Server, and NTLMv2 being used in Server 2008/Vista/7.


Nope. Active Directory uses DNS to resolve names and Kerberos to authenticate computer and user objects.


I don't recall saying anywhere about resolving names. Kerberos is used to authenticate, along with NTLM depending on what services are installed.

I mentioned DNS.

There are two potential serious mistakes that follow from using DNS (or at least using DNS with the same name spaces and with the servers on the same ports).

First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes.

Second mistake: if you do bring your external DNS and internal DNS together (and I've seen this) then anyone anywhere can learn all kinds of interesting things about your internal network.
ID: 966285 · Report as offensive
Profile Mumps [MM]
Volunteer tester
Avatar

Send message
Joined: 11 Feb 08
Posts: 4454
Credit: 100,893,853
RAC: 30
United States
Message 966287 - Posted: 28 Jan 2010, 3:39:42 UTC

Well, I work in an environment where I have an older Samba server offering some shares I need access to that I couldn't access when I upgraded to Windows 7 on my laptop. What I found that worked was to dumb the Windows 7 system down to the older NTLM. I found this on the Web and it worked perfectly fine for me:

On the Windows 7 Laptop:

Control Panel - Administrative Tools - Local Security Policy
Local Policies - Security Options
Network Security: LAN Manager Authentication Level
"Send LM & NTLM Responses"

Minimum session security for NTLM SSP
Disable "Require 128-bit encryption"

This should let your Windows 7 client access shares from a Samba or older Windows based Server. The caveat being that you have now downgraded your Windows 7 client to a much less secure security environment. If your file sharing is all at home and behind a firewall, it's less of a concern. But tighter security is always a good thing in the world of computers these days...

This covers your concerns about being able to access the shares, with your stated issues being the NTLMv2 and 128-bit encryption. But even when I couldn't access my Samba shares, I could still list them. It just couldn't negotiate a secure connection to access them. So your ultimate problem may be different.

In the world of SMB shares, there's normally a BrowseMaster that keeps the list of resources available. And by default, the newest version MS O/S is going to want to take that role. Maybe there's your problem then... As I understand it, the installation of A/D will actually trump the O/S version card. The A/D Domain Controller wins over the latest O/S. And should by default enable the BrowseMaster functionality, whereas your workstation level installation on the Laptop may not have offered to be part of the BrowseMaster elections. Which would leave your older server offering the shares as the BrowseMaster. Which, oh by the way, you can't establish a secure connection to to access the list. Maybe that is the issue. (My Samba server is a member of an A/D Domain so it wouldn't have been the BrowseMaster. So my Win7 Laptop *could* get the list from the network, even when it couldn't authenticate to access the shares...)
ID: 966287 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966295 - Posted: 28 Jan 2010, 3:54:44 UTC - in response to Message 966283.  

To avoid using NTLM and running into compatibility issues, don't use Active Directory.

... the above is the actual pinpoint, and the irony is there for any who care.

Please don't dismiss any technical dissection as "one-upsmanship." It's not. On this questions, there are complexities and many many layers to consider, far more than the typical S@H question. And we have lots of knowledgable people here with direct experience on Interoperability and the history & innards of AD, so if they have something to bring to the table, I prefer they do that rather than limit the conversation to the lowest common denominator.
ID: 966295 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966298 - Posted: 28 Jan 2010, 3:56:19 UTC - in response to Message 966285.  

First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes.

Hi Ned, you mean if someone names their AD tree "MyCompany.COM" instead of bumping it a level such as "Corp.MyCompany.COM" ?? Does DCPromo really let you do that?
ID: 966298 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15692
Credit: 84,761,841
RAC: 28
United States
Message 966302 - Posted: 28 Jan 2010, 4:07:59 UTC - in response to Message 966295.  

To avoid using NTLM and running into compatibility issues, don't use Active Directory.

... the above is the actual pinpoint, and the irony is there for any who care.

Please don't dismiss any technical dissection as "one-upsmanship." It's not. On this questions, there are complexities and many many layers to consider, far more than the typical S@H question. And we have lots of knowledgable people here with direct experience on Interoperability and the history & innards of AD, so if they have something to bring to the table, I prefer they do that rather than limit the conversation to the lowest common denominator.


What you quoted wasn't exactly the context I meant it in. The fact that this couldn't be easily seen by those who are in the know - or more likely that you did know what context but chose to dissect it technically is what makes me waive it off as one-upsmanship.

If someone has something to bring to the table, I'd rather them focus on the actual question at hand instead of focusing on out-of-context comments that weren't written directly from a book and was given in brevity to explain why I believe the advice was bad in the first place.

Al saw it immediately. Why didn't you?
ID: 966302 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15692
Credit: 84,761,841
RAC: 28
United States
Message 966303 - Posted: 28 Jan 2010, 4:09:03 UTC - in response to Message 966298.  

First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes.

Hi Ned, you mean if someone names their AD tree "MyCompany.COM" instead of bumping it a level such as "Corp.MyCompany.COM" ?? Does DCPromo really let you do that?


Or... you can seperate them completely by using MyCompany.LOCAL, though Microsoft Best Practices do prefer the method you described.
ID: 966303 · Report as offensive
Profile Paul D Harris
Volunteer tester

Send message
Joined: 1 Dec 99
Posts: 1122
Credit: 33,600,005
RAC: 0
United States
Message 966305 - Posted: 28 Jan 2010, 4:09:57 UTC
Last modified: 28 Jan 2010, 4:15:44 UTC

@Mumps
Thanks you have the answer on how to configure my win 7 laptop to see my shares on my 2000 Advanced Server and it is good that you explained it very well. But the Active Directory solution did work without having to edit my registry and/or security policies on my laptop win 7.

Paul

PS I just know a lot of people are having this problem, because searches I done for solutions and I found out about win 7 default is ntlmv2 it should or given a choice of one ntlmv2 or the other ntlm or both ntlmv2 + ntlm.
And does ntlmv2 mean NT logon manager ver 2?
ID: 966305 · Report as offensive
Matthew S. McCleary
Avatar

Send message
Joined: 9 Sep 99
Posts: 121
Credit: 2,288,242
RAC: 0
United States
Message 966306 - Posted: 28 Jan 2010, 4:14:01 UTC - in response to Message 966268.  


PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD.


Aw, c'mon, I liked Windows 3.11.
ID: 966306 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966315 - Posted: 28 Jan 2010, 4:32:06 UTC - in response to Message 966302.  

Al saw it immediately. Why didn't you?

Why? Well, sorry, but Ozzie Osbourne is spotty at best in communication. Now then, moving forward, 'Gracious interpretation' is a 2-way street ;-)
ID: 966315 · Report as offensive
1mp0£173
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 8423
Credit: 356,897
RAC: 0
United States
Message 966318 - Posted: 28 Jan 2010, 4:37:05 UTC - in response to Message 966298.  

First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes.

Hi Ned, you mean if someone names their AD tree "MyCompany.COM" instead of bumping it a level such as "Corp.MyCompany.COM" ?? Does DCPromo really let you do that?

I see AD trees named "mycompany.com" all the time.

... but if you've got one named "corp.mycompany.com" and "mycompany.com" is hosted elsewhere, you still have issues.

You either need to make the internal name servers secondary for mycompany.com (so it can resolve things at the ISP) and then get "corp" delegated. This can be exceedingly difficult if you're dealing with a commodity-ISP who can't edit a zone file.

... or, and IMO this is far better, make the internal infrastructure mycompany.local.

At least that way you don't have any confusion over which "mycompany.com" is which.

... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer.
ID: 966318 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 966321 - Posted: 28 Jan 2010, 4:41:39 UTC - in response to Message 966318.  

... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer.


... {sigh} lots of those guys can't architect their way out of a paper bag.
ID: 966321 · Report as offensive
Profile HAL9000
Volunteer tester
Avatar

Send message
Joined: 11 Sep 99
Posts: 6534
Credit: 196,805,888
RAC: 57
United States
Message 966325 - Posted: 28 Jan 2010, 4:44:14 UTC - in response to Message 966321.  

... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer.


... {sigh} lots of those guys can't architect their way out of a paper bag.

That's because it wasn't part of the MCSE class.
SETI@home classic workunits: 93,865 CPU time: 863,447 hours
Join the [url=http://tinyurl.com/8y46zvu]BP6/VP6 User Group[
ID: 966325 · Report as offensive
Previous · 1 · 2 · 3 · Next

Message boards : Number crunching : BOINC and Domain Controller


 
©2026 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.