March 2001
Intermediate to advanced
576 pages
16h 42m
English
Every Windows 2000 domain controller (DC) hosts an instance of the Kerberos service called the Kerberos Key Distribution Center. This means that a client can authenticate to any DC in its own domain. Although Kerberos on Windows 2000 is implemented as a single service, conceptually a Kerberos Authentication Architecture contains several roles. We will discuss the process of using these services in more detail later in the chapter.
The Key Distribution Center is the actual service that runs on every Windows 2000 domain controller. It is started by the local security authority (LSA) and runs in the process space of the LSA. The KDC uses the Active Directory database as its account database. ...
Read now
Unlock full access