March 2001
Intermediate to advanced
576 pages
16h 42m
English
| Q1: | Your DNS zones are set to allow secure updates, but updates are not occurring in the zone. |
| Because the default authentication mechanism for Windows 2000 is Kerberos, the TKEY and TSIG records will use Kerberos by default to authenticate between the DNS client and server. If more than a 5-minute time delta occurs between the Kerberos Key Distribution Center (KDC) and the client, the KDC considers the packets to be part of a replay attack and denies authentication, causing your updates to fail. More importantly, however, if the time is misconfigured between the client and the DC, you will have bigger problems—namely, you will not be able to log on. Usually, this is not a problem because ... |
Read now
Unlock full access