Monday, September 17, 2012

Kerberos skew may still allow login

"Kerberos tickets are issued even though the time difference between the client clock and the domain controller clock is greater than the "Maximum tolerance for computer clock synchronization" value" - KB956627...

Reference:
http://blog.joeware.net/2012/09/17/2599/
http://support.microsoft.com/kb/956627
http://blogs.technet.com/b/askds/archive/2012/08/24/friday-i-mean-saturday-mail-sack-very-wordy-edition.aspx