L
lwoody
Hi all
I am having a problem getting XP SP1 clients using NTLM v2 (AD domain
A) to authenticate (NT4 SP6 domain B) user credentials. These
credentails are used to map a network drive to member servers in the
NT4 based domain.
User logs on to XP SP1 using domain A user id / password. PCs are
domain members of A. They then map a drive to domain B using a
username / password for domain B for some development work.
At the moment, when the user enters their username/password/domain, the
member server logs the logon attempt but appear to fail to pass on the
request to Domain B's DC.
Both domains are on the same LAN. They are not trusted domains (and
they never will). There are no DNS/WINS issues. The DCs can ping each
other. This arrangement previously worked when Domain A was NT4 based.
It stopped working since it was replaced with XP / Active Directory.
Research suggests that I have add the (previously missing)
HKLM\system\currentcontrolset\control\lsa\lmcompatabilitylevel registry
key to both Domain B NT4 DC's with a value of 1.
This does not work.
XP SP1 clients set to "Send NTLMv2 response only"
NT4 Domain were set to "MS default" which is NTLM and now have the key
added which should negotiate NTLMv2?
As a note, from my XP SP1, I can authenticate to Domain B only to the
NT4 domain controllers before making the registry change (still works
afterwards) - but not to any of the member servers which are a mixture
of NT4, 2000, 2003 using the same user id.
Any ideas where I need to look?
I am having a problem getting XP SP1 clients using NTLM v2 (AD domain
A) to authenticate (NT4 SP6 domain B) user credentials. These
credentails are used to map a network drive to member servers in the
NT4 based domain.
User logs on to XP SP1 using domain A user id / password. PCs are
domain members of A. They then map a drive to domain B using a
username / password for domain B for some development work.
At the moment, when the user enters their username/password/domain, the
member server logs the logon attempt but appear to fail to pass on the
request to Domain B's DC.
Both domains are on the same LAN. They are not trusted domains (and
they never will). There are no DNS/WINS issues. The DCs can ping each
other. This arrangement previously worked when Domain A was NT4 based.
It stopped working since it was replaced with XP / Active Directory.
Research suggests that I have add the (previously missing)
HKLM\system\currentcontrolset\control\lsa\lmcompatabilitylevel registry
key to both Domain B NT4 DC's with a value of 1.
This does not work.
XP SP1 clients set to "Send NTLMv2 response only"
NT4 Domain were set to "MS default" which is NTLM and now have the key
added which should negotiate NTLMv2?
As a note, from my XP SP1, I can authenticate to Domain B only to the
NT4 domain controllers before making the registry change (still works
afterwards) - but not to any of the member servers which are a mixture
of NT4, 2000, 2003 using the same user id.
Any ideas where I need to look?