You receive a Kerberos PAC validation error message when you start multiple processes on multiple Windows Server 2008-based computers

You receive a Kerberos PAC validation error message when you start multiple processes on multiple Windows Server 2008-based computers

Article ID : 954409
Last Review : July 11, 2008
Revision : 1.0

SYMPTOMS

Consider the following scenario:

• You start multiple processes on multiple Windows Server 2008-based computers from domains that do not directly trust one another.
• The processes have to validate the Kerberos Privilege Attribute Certificate (PAC).

In this scenario, the processes do not authenticate one another. Additionally, you receive a Kerberos PAC validation error message.

CAUSE

This issue occurs because Kerberos PAC validation relies on Net Logon generic pass-through authentication. This authentication is supported only for domains that are directly trusted. For more information about trusts, visit the following Microsoft TechNet Web site:

http://technet2.microsoft.com/windowsserver/en/library/b6284369-73ea-4d68-a3a5-975a0fe6782d1033.mspx?mfr=true (http://technet2.microsoft.com/windowsserver/en/library/b6284369-73ea-4d68-a3a5-975a0fe6782d1033.mspx?mfr=true)

APPLIES TO
• Windows Server 2008 Enterprise
• Windows Server 2008 Datacenter
• Windows Server 2008 Standard
• Windows Web Server 2008
• Windows Server 2008 for Itanium-Based Systems

Back to the top

Keywords: 
kbprb kbexpertiseadvanced kbtshoot KB954409

 

Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
Microsoft Corporation. All rights reserved. Terms of Use | Trademarks


You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

AddThis Social Bookmark Button

Leave a Reply

*
To prove that you're not a bot, enter this code
Anti-Spam Image