Re: [Samba] [SamLogon, network] vs [Kerberos KDC, ENC-TS Pre-authentication]


No one knows..?

My guess is:
- SamLogon,network is an interactive logon, so a user typing a password on a windows domain joined workstation

- Kerberos KDC,ENC-TS Pre-authentication is something like: an already logged on user accessing another server within the same AD doain

But is what I guess true...? :-)


On 03/22/2018 10:34 AM, mj via samba wrote:

This is just curiosity.

We are monitoring failed logons, and there seem to be three types:

- LDAP,simple bind/TLS
(obious, failed ldap logons)

and these two:
- SamLogon,network
- Kerberos KDC,ENC-TS Pre-authentication

Could someone explain what (the difference between) these two types is?

Google doesn't really seem to help.


