Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Configuring ADSSO on windows 2008

I am confused with the syntax of ktpass utility on windows 2008.

I have gone through this microsoft document but could not sort it out.

http://technet.microsoft.com/en-us/library/cc753771.aspx#BKMK_examples

If someone can give an example or steps for ktpass utility for win2008.

12 REPLIES
New Member

Re: Configuring ADSSO on windows 2008

It's to much to paste here, but the full server manual does a good job of explaining all of the options. Here's a link to the AD SSO section on CCO (no login required):

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/45/cas/s_adsso.html#wp1174556

New Member

Re: Configuring ADSSO on windows 2008

Hello Micheal,

These are the instruction for windows 2003. but i have to use the ktpass on windows 2008.

The syntax of ktpass is different in win2008.

Can you just type the syntax of ktpass for me for windows 2008

New Member

Re: Configuring ADSSO on windows 2008

Sorry, didn't realize the syntax was different. We are running ours on 2003 and I don't have access to a 2008 server to test it with.

Re: Configuring ADSSO on windows 2008

Hi,

What's the exact error that you are getting? Can you paste it here?

Sam

Gold

Re: Configuring ADSSO on windows 2008

after the "-mapuser" switch is the username for the adsso account. although the example gives it in the following format:

"... -mapuser username..."

i've had to use the following format to get it to work:

"... -mapuser domain\username..."

This was for an error that said it couldn't find the domain or something like that.

http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080884229.shtml

Re: Configuring ADSSO on windows 2008

Hi,

You do not have to give that as domain\username, since you are providing that information after the -princ switch.

Check it and let me know.

Sam

Re: Configuring ADSSO on windows 2008

Hi,

Did this solve your problem?

Sam

New Member

Re: Configuring ADSSO on windows 2008

Hi,

Man it was holiday for 2 days. I will be trying on Monday.

However can you write the ktpass command syntax for me for Windows 2008. I think that there is a difference between the the syntax of windows 2003 and 2008.

Gold

Re: Configuring ADSSO on windows 2008

i've done installs where i had to enter it there and where i haven't - regardless of the -princ switch.

New Member

Re: Configuring ADSSO on windows 2008

Hello Sure,

Which win OS you were using. Are you sure it was windows 2008.

Re: Configuring ADSSO on windows 2008

Cisco NAC Appliance Agent/AD Server Compatibility for AD SSO

http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/agntsprt.html#wp55522

Single Domain AD SSO is supported on Windows 2008 Enterprise SP1.


Windows 2008 Enterprise SP1 started with 4.1.8 or 4.5.0.


-What version of CCA are you running

-What version of Windows are you running

-Is it a single domain.

-Are you trying to configure against a single server or a domain

-What version of KTPASS are you using. 

Cisco recommends using release 5.2.3790.0 of the KTPass executable.

-What is the extact CLI command that you are entering.

-What does the CAS logs show for the failed attempt.

 

Check out the Chalk Talk -

Chalk Talk 8: Configuring Authentication, Roles, and SSO

Slide 70

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps8418/ps6128/prod_presentation0900aecd80549168.html

Re: Configuring ADSSO on windows 2008

Disable UAC on windows server and try.

413
Views
0
Helpful
12
Replies
CreatePlease login to create content