Re: [Samba] [SamLogon, network] vs [Kerberos KDC, ENC-TS Pre-authentication]
- Date: Mon, 26 Mar 2018 20:13:43 +1300
- From: Andrew Bartlett via samba <samba@xxxxxxxxxxxxxxx>
- Subject: Re: [Samba] [SamLogon, network] vs [Kerberos KDC, ENC-TS Pre-authentication]
On Mon, 2018-03-26 at 09:08 +0200, mj via samba wrote:
> No one knows..?
> My guess is:
> - SamLogon,network is an interactive logon, so a user typing a password
> on a windows domain joined workstation
No, that would be SamLogon,interactive.
SamLogon,network is NTLM authentication accessing another server in the
domain (in general).
> - Kerberos KDC,ENC-TS Pre-authentication is something like: an already
> logged on user accessing another server within the same AD doain
No, that is most likely a user getting their first ticket on logon.
I'm glad to hear you are making good use of the audit log feature.
I hope this helps,
Andrew Bartlett http://samba.org/~abartlet/
Authentication Developer, Samba Team http://samba.org
Samba Developer, Catalyst IT http://catalyst.net.nz/services/samba
To unsubscribe from this list go to the following URL and read the