OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Win2K anf NTLM2
From: Myung Bang (myung.bangJLAB.ORG)
Date: Mon Sep 18 2000 - 15:50:26 CDT


I was doing some testing with NT security and came acrossed something
weired with Win2K client. I have a NT 4.0 Master domain and with all NT
DCs, servers and clients have SP6a installed. Within the domain, there
are few Win2K clients, also. I was going to set the LMCompatibilityLevel
to 5 on all DCs, Servers and clients. Right now, all DCs are set to 0
(by default).

I changed the LMCompatibilityLevel to 5 on one NT 4.0 client machine
(all DCs are still level 0) and that machine was able to login to the
domain as I expected. Then I changed the LMCompatibilityLevel to 5 on
Win2K machine, and it could NOT login to the domain. Then I changed
LMCompatibilityLevel to 4 and 3, but still can't login. I changed
LMCompatibilityLevel to 0 and it will let me login again.
LMCompatibilityLevel 0, 1, and 2 will let me login.

All documents states that clients with LMCompatibilityLevel 5-0 can
login to Domain where DCs with LMCompatibilityLevel 0. Is this a bug in
Win2K?

Thanks.
Myung