PC Review


Reply
Thread Tools Rate Thread

Saved passwords problem

 
 
Steve Garwood
Guest
Posts: n/a
 
      12th Feb 2004
I have read tons of messages about saved RDP password problems with
shared machines, but I haven't seen this problem, though it's probably
related...

Client: Windows XP RDP
Client Domain: DomainA
TermServ: Windows 2000 Advanced Server
TermServ Domain: DomainB (no trusts between DomainA and DomainB)

Phase 1:
User saves his TermServ credentials in an rdp file.
For several weeks, user successfully uses this rdp file to autologon
to the TS.

Phase 2:
User changes his DomainA password
After the user logs off and logs on again, the RDP credentials no
longer work
If the user resaves the RDP file with the EXACT same DomainB password
as in Phase 1, autologon works again until the next DomainA password
change.


My theory:
It would appear the the user's cached DomainA credentials are used as
the encryption salt for the saved RDP password and, after changing the
password and logging off and on, the original salt is no longer
available for decrypting the saved password. Seems plausible, but I
have no idea if I'm right.

My question:
Is there any workaround for this other than installing the OCX and
scripting the OCX?

Thanks.

Steve Garwood
(E-Mail Removed)
 
Reply With Quote
 
 
 
 
Ivan Leichtling [MSFT]
Guest
Posts: n/a
 
      17th Feb 2004
The windows cryptography APIs we use do make use of a key derived in
part from the user's domain password. There is no true work around.

On 12 Feb 2004 12:30:22 -0800, (E-Mail Removed) (Steve
Garwood) wrote:

>I have read tons of messages about saved RDP password problems with
>shared machines, but I haven't seen this problem, though it's probably
>related...
>
>Client: Windows XP RDP
>Client Domain: DomainA
>TermServ: Windows 2000 Advanced Server
>TermServ Domain: DomainB (no trusts between DomainA and DomainB)
>
>Phase 1:
>User saves his TermServ credentials in an rdp file.
>For several weeks, user successfully uses this rdp file to autologon
>to the TS.
>
>Phase 2:
>User changes his DomainA password
>After the user logs off and logs on again, the RDP credentials no
>longer work
>If the user resaves the RDP file with the EXACT same DomainB password
>as in Phase 1, autologon works again until the next DomainA password
>change.
>
>
>My theory:
>It would appear the the user's cached DomainA credentials are used as
>the encryption salt for the saved RDP password and, after changing the
>password and logging off and on, the original salt is no longer
>available for decrypting the saved password. Seems plausible, but I
>have no idea if I'm right.
>
>My question:
>Is there any workaround for this other than installing the OCX and
>scripting the OCX?
>
>Thanks.
>
>Steve Garwood
>(E-Mail Removed)


This posting is provided "AS IS" with no warranties, and confers no rights
 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Passwords are not being saved Richard Microsoft Outlook Discussion 2 27th Jul 2009 08:33 PM
Saved Passwords Donald Jacobs Windows XP General 4 23rd Apr 2007 04:06 PM
Problem with saved passwords Eli Windows XP Help 0 20th Feb 2005 11:57 PM
passwords not saved nick Windows XP General 0 23rd Nov 2003 07:56 PM
My passwords are not being saved Jim Windows XP General 1 28th Oct 2003 02:14 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 03:15 PM.