disabled users

  • Thread starter Thread starter maro
  • Start date Start date
M

maro

hello,
our environment consists of the following:
a windows 2000 domain and a kerberos realm on unix.
usernames in active directory are mapped to user
principals on the kerberos realm. passwords are
different.users do not log to windows domain, they log to
kerberos realm.
When i want to disable a user account, i disable it in
active directory, however the user can still login to
kerberos realm.
is this normal????????????
thanks
 
Yes if your users are created in and for the Kerberos realm. You stated
that your users never log into the 2000 domain. Consider domain and realm
to be equal. Meaning 2 seperate enitities that both use kerberos but that's
thier only link.
 
Back
Top