Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

Hi,

Does the Secure Channel Password change whenever one restarts the server?

Thanks

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.security (More info?)

 

By default the computer account passwords used for secure channel in a
domain are changed by the computer every thirty days. My understanding is
that if it computer misses the password change interval twice the domain
controller will disable the computer account. The netdiag support tool when
run on a domain computer will detect if the secure channel to the domain is
in place or not. --- Steve


"Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
message news:4AF99BD3-828D-43A4-98E7-4A11D7507BDD@microsoft.com...
> Hi,
>
> Does the Secure Channel Password change whenever one restarts the server?
>
> Thanks

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

Thanks for the reply.

Is there anyway to find out the date when the password changes? Does it
change at the end of each month?

Thanks

"Steven L Umbach" wrote:

> By default the computer account passwords used for secure channel in a
> domain are changed by the computer every thirty days. My understanding is
> that if it computer misses the password change interval twice the domain
> controller will disable the computer account. The netdiag support tool when
> run on a domain computer will detect if the secure channel to the domain is
> in place or not. --- Steve
>
>
> "Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
> message news:4AF99BD3-828D-43A4-98E7-4A11D7507BDD@microsoft.com...
> > Hi,
> >
> > Does the Secure Channel Password change whenever one restarts the server?
> >
> > Thanks
>
>
>

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

That's a good question that I don't know the answer to. I don't believe it
would be the end of the month but somewhere near thirty days. The tools
nltest and netdom may prove helpful, but I am not sure though they have a
lot of options. --- Steve


"Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
message news:79C93B86-EA11-4DF6-8963-9D6A7F98B069@microsoft.com...
> Thanks for the reply.
>
> Is there anyway to find out the date when the password changes? Does it
> change at the end of each month?
>
> Thanks
>
> "Steven L Umbach" wrote:
>
>> By default the computer account passwords used for secure channel in a
>> domain are changed by the computer every thirty days. My understanding is
>> that if it computer misses the password change interval twice the domain
>> controller will disable the computer account. The netdiag support tool
>> when
>> run on a domain computer will detect if the secure channel to the domain
>> is
>> in place or not. --- Steve
>>
>>
>> "Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
>> message news:4AF99BD3-828D-43A4-98E7-4A11D7507BDD@microsoft.com...
>> > Hi,
>> >
>> > Does the Secure Channel Password change whenever one restarts the
>> > server?
>> >
>> > Thanks
>>
>>
>>

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

I knew that the default is to provide membership safeguard by
retaining machine account passwords two deep, so the auth can
be with the prior if the password presented by the machine does
not match the current password. This provides for a little tolerance
for such as reimaging, etc..
What I did not know was that the account would be disabled if
two password changes were missed, and I have to question this.
One can disable, on a per-machine (or OU via GPO) basis whether
a machine will change its password at all. This means if there is
such a disabling, then the mechanism could not be blind to the
policy under which the machine that has not changed it password
operates, etc. - all becoming a little complex. Of course, if this
is so, that also means that if a machine is not booted for a couple
months then its membership is automatically defunct.

--
Roger Abell

"Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> wrote in message
news:NxPtd.160071$V41.127540@attbi_s52...
> By default the computer account passwords used for secure channel in a
> domain are changed by the computer every thirty days. My understanding is
> that if it computer misses the password change interval twice the domain
> controller will disable the computer account. The netdiag support tool
when
> run on a domain computer will detect if the secure channel to the domain
is
> in place or not. --- Steve
>
>
> "Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
> message news:4AF99BD3-828D-43A4-98E7-4A11D7507BDD@microsoft.com...
> > Hi,
> >
> > Does the Secure Channel Password change whenever one restarts the
server?
> >
> > Thanks
>
>

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

Hi Roger.

I may be wrong on that. Below is the source of my information. Maybe I
misinterpreted it and they were referring to NT4.0? I can put a test
computer on vacation but I won't know the results for 61 days [unless I
change a few computer clocks]. --- Steve

http://www.windowsnetworking.com/k [...] anges.html
http://tinyurl.com/46wr9 -- same link, shorter.

"Roger Abell" <mvpNOSpam@asu.edu> wrote in message
news:OoARuxr3EHA.3000@TK2MSFTNGP15.phx.gbl...
>I knew that the default is to provide membership safeguard by
> retaining machine account passwords two deep, so the auth can
> be with the prior if the password presented by the machine does
> not match the current password. This provides for a little tolerance
> for such as reimaging, etc..
> What I did not know was that the account would be disabled if
> two password changes were missed, and I have to question this.
> One can disable, on a per-machine (or OU via GPO) basis whether
> a machine will change its password at all. This means if there is
> such a disabling, then the mechanism could not be blind to the
> policy under which the machine that has not changed it password
> operates, etc. - all becoming a little complex. Of course, if this
> is so, that also means that if a machine is not booted for a couple
> months then its membership is automatically defunct.
>
> --
> Roger Abell
>
> "Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> wrote in message
> news:NxPtd.160071$V41.127540@attbi_s52...
>> By default the computer account passwords used for secure channel in a
>> domain are changed by the computer every thirty days. My understanding is
>> that if it computer misses the password change interval twice the domain
>> controller will disable the computer account. The netdiag support tool
> when
>> run on a domain computer will detect if the secure channel to the domain
> is
>> in place or not. --- Steve
>>
>>
>> "Amir Marathonian" <AmirMarathonian@discussions.microsoft.com> wrote in
>> message news:4AF99BD3-828D-43A4-98E7-4A11D7507BDD@microsoft.com...
>> > Hi,
>> >
>> > Does the Secure Channel Password change whenever one restarts the
> server?
>> >
>> > Thanks
>>
>>
>
>

Reply to Anonymous
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Secure Channel Password
Go to:

There are 596 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them