MCSE/MCSA Implementing and Administering Security in a Windows 2000 Network: Study Guide and DVD Training System (Exam 70-214)

Although Windows 2000 provides support for several authentication methods, only NTLM and Kerberos authenticate network users. Other methods authenticate dial-in users and users who access the network over the Internet, such as those accessing a Web or File Transfer Protocol (FTP) site.

The two supported network authentication methods in Windows 2000 are:

By default, Kerberos is used for all network authentications in Windows 2000, except in the following situations:

NTLM

NTLM is the mainstay of Windows NT and was once considered a relatively powerful protocol. However, NTLM suffers compared to Kerberos for several reasons:

However, NTLM is necessary for establishing trusts with NT domains and for authenticating down-level NT clients. LAN Manager (LM) is used for authenticating Windows 3.x and Windows 9.x clients. By default, Windows 2000 is installed in mixed mode, meaning it can use any combination of Windows NT 4.0 and Windows 2000 domain controllers. After upgrading all of their computers (domain controllers and clients) to Windows 2000, security analyst's can disable LM and NTLM authentication, thereby increasing their overall authentication security.

Note 

Windows 95, Windows 98, and Windows NT 4.0 clients running the directory services client (dsclient.exe) can use NTLMv2 for authentication. The Windows 9.x directory services client is located in the clients\win9x folder on the Windows 2000 Server CD-ROM. The Windows NT 4.0 directory services client can be downloaded from http://support.microsoft.com/default.aspx?scid=KB;en-us;288358. Microsoft has not produced a version of the dsclient specifically for Windows Me and does not support using the dsclient on Windows Me.

Kerberos

Kerberos is the default network authentication method in Windows 2000 because it is more secure, flexible, and efficient than NTLM. Using Kerberos instead of NTLM provides the following benefits to networks:

Категории