windows server showing mapped domain user name for server principal in KCD environment rather than the client logon

hello,

when authenticating via kcd, the windows server is showing the mapped domain user name ( as in the mapuser parameter from ktpass) as the logged in user rather than the user that the user ticket was requested for.

Any explanation for this behavior or Is there any server side configuration to modify this?

September 1st, 2015 12:00pm

when authenticating via kcd, the windows server is showing the mapped domain user name ( as in the mapuser parameter from ktpass) as the logged in user rather than the user that the user ticket was requested for.

Hi,

By "kcd", do you mean "KDC"?

In addition, would you tell us that where/how did you see "the windows server is showing the mapped domain user name ( as in the mapuser parameter from ktpass) as the logged in user rather than the user that the user ticket was requested for"?

Best Regards,

Amy

Free Windows Admin Tool Kit Click here and download it now
September 3rd, 2015 10:32pm

hello.

by KCD I mean kerberos constrained delegation.

but yes, of course I'm getting valid ticket from the KDC on behalf of the user (client that is actually logging on).

iis logs on the windows server shows the mapped domain user rather than the real client creds,

In the case of sharepoint it even displays this user.

Let me know if I can provide more informatione,

Kind Regards.

September 4th, 2015 5:26pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics