<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx</link><description>Kerberos is well… Kerberos. And NTLM is NTLM right? Right. Most of the time. This post is from a recent hotfix I worked on where it was made painfully clear that this isn’t always true. Here is a cool overview stolen from msdn And the following table</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#1846758</link><pubDate>Fri, 09 Mar 2007 22:00:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1846758</guid><dc:creator>KaPes</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;We also had encountered the same problem on one of the machine, and searching for those events on eventid.net, we tried some solution listed there. One of them was to set MTU of the network right. After setting the MTU it solved the problem.&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#1847957</link><pubDate>Sat, 10 Mar 2007 01:05:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1847957</guid><dc:creator>SpatDSG</dc:creator><description>&lt;p&gt;Ah good information. Thanks!&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#3838589</link><pubDate>Fri, 13 Jul 2007 03:12:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3838589</guid><dc:creator>BJSmithCO</dc:creator><description>&lt;p&gt;What is the response of the system if the PAC information is not provided in the ticket (NO_AUTH_DATA_REQUIRED)? Does this basically cripple a Win2003 server? Can users still authenticate and gain authorizations to access network resources, or do they just have a ticket to nowhere? I'm looking at removing the PAC as a means to enable Solaris 8 users to authenticate directly against AD2003 (where Solaris Kerberos only talks UDP), but I'm concerned about the effect on my Windows users.&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#7448676</link><pubDate>Tue, 05 Feb 2008 01:24:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7448676</guid><dc:creator>Venkat</dc:creator><description>&lt;p&gt;Why are we doing a PAC verification for a computer account while doing a logon? &lt;/p&gt;
&lt;p&gt;I thought PAC verification is carried out only if a service is run as a user account and not with local system.&lt;/p&gt;
&lt;p&gt;Since the computer account would have the Tcbprivilege, why do we do a PAC validation?&lt;/p&gt;
</description></item><item><title>More Kerberos fun with PAC’s</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#9512535</link><pubDate>Fri, 27 Mar 2009 03:53:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9512535</guid><dc:creator>Spat's WebLog (Steve Patrick)</dc:creator><description>&lt;p&gt;I had been meaning to blog about this for a while, and recently was teaching a class when a friend of&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#9599501</link><pubDate>Sat, 09 May 2009 21:39:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9599501</guid><dc:creator>OpenSpecification</dc:creator><description>&lt;p&gt;Edgar's post on Open Specification blog: Understanding Microsoft Kerberos PAC Validation&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#9908187</link><pubDate>Fri, 16 Oct 2009 14:01:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9908187</guid><dc:creator>Ross</dc:creator><description>&lt;p&gt;I know this is an old topic and I hate to be a bit stroppy here, but as a Network guy who has just experienced this problem...&lt;/p&gt;
&lt;p&gt;You have a fault that causes all apps to be uninstalled if the network &amp;quot;fails&amp;quot; or experiences a &amp;quot;transient fault&amp;quot;. &amp;nbsp;Hello - wireless roaming anyone? 3G access in trains? VPN's over the internet? &lt;/p&gt;
&lt;p&gt;Sorry, but how can this ever be interpreted as a network issue? Network connections come and go (sometimes for very good reasons - congested hubs / access lists/firewalls.), The application should simply acknowledge the failure to complete the authentication and move on - not trigger this type of event.&lt;/p&gt;
&lt;p&gt;Be fair, this is plainly an unfortunate oversight or poor coding.&lt;/p&gt;
</description></item><item><title>re: Kerberos PAC Validation… what is it?</title><link>http://blogs.msdn.com/spatdsg/archive/2007/03/07/pac-validation.aspx#9915905</link><pubDate>Sun, 01 Nov 2009 18:16:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9915905</guid><dc:creator>SpatDSG</dc:creator><description>&lt;p&gt;Agreed! That's why we developed the hotfix in &lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/?kbid=929624"&gt;http://support.microsoft.com/?kbid=929624&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>