Message boards :
Number crunching :
BOINC and Domain Controller
Message board moderation
Previous · 1 · 2 · 3 · Next
| Author | Message |
|---|---|
|
Matthew S. McCleary Send message Joined: 9 Sep 99 Posts: 121 Credit: 2,288,242 RAC: 0
|
@ozzfan Nope. Active Directory uses DNS to resolve names and Kerberos to authenticate computer and user objects.
|
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
Active Directory .... Kerberos to authenticate computer and user objects. Spot on Flain, plus including kerberos aware apps, assuming all parties are in a AD domain model (and kerb rhelm), ideally Native Mode, as mixed mode still has an emulated PDC w/NTLM auth services. But keep in mind there is still SPNEGO to negotiate downwards and/or across the river. Most of the cross model SMB sharing access problems I've seen in recent years are resolved by knowing how to set up a session and passing through a valid set of credentials (between two computers that agree on the current TIME). PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD. |
HAL9000 Send message Joined: 11 Sep 99 Posts: 6534 Credit: 196,805,888 RAC: 57
|
Active Directory .... Kerberos to authenticate computer and user objects. Yeah they should really be using WFW 3.12. SETI@home classic workunits: 93,865 CPU time: 863,447 hours Join the [url=http://tinyurl.com/8y46zvu]BP6/VP6 User Group[
|
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
Right on, Hal, and we all know WFW hasn't been the same since Andre the Giant passed away :( |
Pappa Send message Joined: 9 Jan 00 Posts: 2562 Credit: 12,301,681 RAC: 0
|
@ozzfan The simple reason is, it adds a layer of "complexity" that did not solve your problem (or others). So while the discussion has drifted away........... Regards Please consider a Donation to the Seti Project. |
OzzFan ![]() Send message Joined: 9 Apr 02 Posts: 15692 Credit: 84,761,841 RAC: 28
|
@ozzfan I don't recall saying anywhere about resolving names. Kerberos is used to authenticate, along with NTLM depending on what services are installed. |
OzzFan ![]() Send message Joined: 9 Apr 02 Posts: 15692 Credit: 84,761,841 RAC: 28
|
PS: And whomever is still running WfW 3.11 should probably consider turning that off before advising others to not consider AD. I'll take that as a direct comment to me since I'm the only one in this thread having admitted to running WfW 3.11 - perhaps you should consider what motives I may have before suggesting that I turn it off. Further, AD is not needed on every Windows network. I never said that it shouldn't be considered, I stated that it wasn't the best solution for PaulDHarris's situation if he's only running one server, or more specifically, against previous advice that was given to him as mentioned in his message earlier in the thread: ...I got my win 7 laptop I could not open any shares on my server because of ntlmv2 in win 7 and pre win 7 uses ntlm and so win 7 does not see the earlier server shares. I was told to install active directory which is domain controller and now I can see my shares on my win 7 laptop but BOINC won't install on my server because it is now a domain controller... It wasn't necessary to install AD to access his shares, or to even see them for that matter. Perhaps those of you with a little knowledge of the situation could offer better advice instead of trying to play this game of one-upsmanship that is so often rift on these boards with techies. |
OzzFan ![]() Send message Joined: 9 Apr 02 Posts: 15692 Credit: 84,761,841 RAC: 28
|
@ozzfan Thank you Al. That's exactly what I was getting at. |
|
1mp0£173 Send message Joined: 3 Apr 99 Posts: 8423 Credit: 356,897 RAC: 0
|
@ozzfan I mentioned DNS. There are two potential serious mistakes that follow from using DNS (or at least using DNS with the same name spaces and with the servers on the same ports). First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes. Second mistake: if you do bring your external DNS and internal DNS together (and I've seen this) then anyone anywhere can learn all kinds of interesting things about your internal network. |
Mumps [MM] Send message Joined: 11 Feb 08 Posts: 4454 Credit: 100,893,853 RAC: 30
|
Well, I work in an environment where I have an older Samba server offering some shares I need access to that I couldn't access when I upgraded to Windows 7 on my laptop. What I found that worked was to dumb the Windows 7 system down to the older NTLM. I found this on the Web and it worked perfectly fine for me: On the Windows 7 Laptop: Control Panel - Administrative Tools - Local Security Policy Local Policies - Security Options Network Security: LAN Manager Authentication Level "Send LM & NTLM Responses" Minimum session security for NTLM SSP Disable "Require 128-bit encryption" This should let your Windows 7 client access shares from a Samba or older Windows based Server. The caveat being that you have now downgraded your Windows 7 client to a much less secure security environment. If your file sharing is all at home and behind a firewall, it's less of a concern. But tighter security is always a good thing in the world of computers these days... This covers your concerns about being able to access the shares, with your stated issues being the NTLMv2 and 128-bit encryption. But even when I couldn't access my Samba shares, I could still list them. It just couldn't negotiate a secure connection to access them. So your ultimate problem may be different. In the world of SMB shares, there's normally a BrowseMaster that keeps the list of resources available. And by default, the newest version MS O/S is going to want to take that role. Maybe there's your problem then... As I understand it, the installation of A/D will actually trump the O/S version card. The A/D Domain Controller wins over the latest O/S. And should by default enable the BrowseMaster functionality, whereas your workstation level installation on the Laptop may not have offered to be part of the BrowseMaster elections. Which would leave your older server offering the shares as the BrowseMaster. Which, oh by the way, you can't establish a secure connection to to access the list. Maybe that is the issue. (My Samba server is a member of an A/D Domain so it wouldn't have been the BrowseMaster. So my Win7 Laptop *could* get the list from the network, even when it couldn't authenticate to access the shares...) |
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
To avoid using NTLM and running into compatibility issues, don't use Active Directory. ... the above is the actual pinpoint, and the irony is there for any who care. Please don't dismiss any technical dissection as "one-upsmanship." It's not. On this questions, there are complexities and many many layers to consider, far more than the typical S@H question. And we have lots of knowledgable people here with direct experience on Interoperability and the history & innards of AD, so if they have something to bring to the table, I prefer they do that rather than limit the conversation to the lowest common denominator. |
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes. Hi Ned, you mean if someone names their AD tree "MyCompany.COM" instead of bumping it a level such as "Corp.MyCompany.COM" ?? Does DCPromo really let you do that? |
OzzFan ![]() Send message Joined: 9 Apr 02 Posts: 15692 Credit: 84,761,841 RAC: 28
|
To avoid using NTLM and running into compatibility issues, don't use Active Directory. What you quoted wasn't exactly the context I meant it in. The fact that this couldn't be easily seen by those who are in the know - or more likely that you did know what context but chose to dissect it technically is what makes me waive it off as one-upsmanship. If someone has something to bring to the table, I'd rather them focus on the actual question at hand instead of focusing on out-of-context comments that weren't written directly from a book and was given in brevity to explain why I believe the advice was bad in the first place. Al saw it immediately. Why didn't you? |
OzzFan ![]() Send message Joined: 9 Apr 02 Posts: 15692 Credit: 84,761,841 RAC: 28
|
First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes. Or... you can seperate them completely by using MyCompany.LOCAL, though Microsoft Best Practices do prefer the method you described. |
Paul D Harris Send message Joined: 1 Dec 99 Posts: 1122 Credit: 33,600,005 RAC: 0
|
@Mumps Thanks you have the answer on how to configure my win 7 laptop to see my shares on my 2000 Advanced Server and it is good that you explained it very well. But the Active Directory solution did work without having to edit my registry and/or security policies on my laptop win 7. Paul PS I just know a lot of people are having this problem, because searches I done for solutions and I found out about win 7 default is ntlmv2 it should or given a choice of one ntlmv2 or the other ntlm or both ntlmv2 + ntlm. And does ntlmv2 mean NT logon manager ver 2? |
|
Matthew S. McCleary Send message Joined: 9 Sep 99 Posts: 121 Credit: 2,288,242 RAC: 0
|
Aw, c'mon, I liked Windows 3.11.
|
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
Al saw it immediately. Why didn't you? Why? Well, sorry, but Ozzie Osbourne is spotty at best in communication. Now then, moving forward, 'Gracious interpretation' is a 2-way street ;-) |
|
1mp0£173 Send message Joined: 3 Apr 99 Posts: 8423 Credit: 356,897 RAC: 0
|
First mistake is when someone sets up a network, and uses a valid internet domain when they set up the server. I have more than a few customers who cannot access their own web sites because AD uses DNS, and we have the same name space used for two purposes. I see AD trees named "mycompany.com" all the time. ... but if you've got one named "corp.mycompany.com" and "mycompany.com" is hosted elsewhere, you still have issues. You either need to make the internal name servers secondary for mycompany.com (so it can resolve things at the ISP) and then get "corp" delegated. This can be exceedingly difficult if you're dealing with a commodity-ISP who can't edit a zone file. ... or, and IMO this is far better, make the internal infrastructure mycompany.local. At least that way you don't have any confusion over which "mycompany.com" is which. ... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer. |
52 Aces Send message Joined: 7 Jan 02 Posts: 497 Credit: 14,261,068 RAC: 67
|
... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer. ... {sigh} lots of those guys can't architect their way out of a paper bag. |
HAL9000 Send message Joined: 11 Sep 99 Posts: 6534 Credit: 196,805,888 RAC: 57
|
... and when I see "mycompany.com" I frequently find that the server was sold by a consultant who is a Microsoft Certified Systems Engineer. That's because it wasn't part of the MCSE class. SETI@home classic workunits: 93,865 CPU time: 863,447 hours Join the [url=http://tinyurl.com/8y46zvu]BP6/VP6 User Group[
|
©2026 University of California
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.