Pharos Active Directory LDAP Plug-in Update Rev 409

Prev Next

This update replaces the Pharos Active Directory LDAP Logon Plug-in, adldaplogon.exe, version 9.2.10000.409, and adds support for Kerberos authentication.

Before You Start

  • This update should be applied to installations using Uniprint Suite 9.2.

  • It applies only if your site uses the Pharos Active Directory LDAP Plug-in as a Logon plug-in. If you authenticate using a script or another plug-in, this update is not required.

  • This plug-in is not delivered by the Updater Service. It is a single executable that you copy into place, as described below.

  • You will need permission to write to the Pharos\bin directory on your Pharos servers, and an elevated command prompt to change the authentication mode, because that setting is stored in HKEY_LOCAL_MACHINE.

  • This update relates to Microsoft's phasing out of NTLM authentication in Windows. Applying it does not change how your system authenticates users; moving to Kerberos is a separate, deliberate step. See Details below.

  • If you also authenticate using a scripted Logon plug-in, apply the Print Server Update, and the SignUp Server Update if you run the SignUp Service.

Installation

  1. Download the plug-in from the Pharos Hot Fixes web page.

  2. In the properties of the downloaded file, choose to unblock, and then unzip it.

  3. Copy adldaplogon.exe into the Pharos\bin directory of all Pharos servers that use the plug-in, replacing the existing copy. This is typically C:\Program Files\Pharos\bin\.

  4. Confirm the plug-in is working by testing it against a known account before changing anything else:
    adldaplogon.exe C:\Temp\result.txt "trace" "jsmith" "<password>" "Keyboard"
    The result file will contain OK on success. Trace output now states the active authentication mode before any bind is attempted.

Your existing configuration is preserved. The server list and all other registry settings are untouched, and there is no need to add your servers again.

The application of this update constitutes acceptance of the conditions specified in your license agreement. To view the license agreement, please refer to the license.rtf file on your Pharos CD.

Details

Microsoft is phasing out NTLM authentication in Windows and will disable network NTLM by default in a future Windows release. This update extends the plug-in so that Kerberos can be used, and can be mandated rather than left to Windows to choose.

  • New authentication mode setting. A new setup command selects the protocol used to validate credentials:
    adldaplogon --auth-mode <ntlm | kerberos>
    The value is stored in the registry as AuthMode under the plug-in's existing AdLdapLogon key. An unrecognised value is reported as an error rather than being silently defaulted.

  • The mode defaults to NTLM. Applying this update does not change an existing setting, so the plug-in continues to behave exactly as it did until you change the mode yourself.

  • The mode is a per-server setting, because it is stored under HKEY_LOCAL_MACHINE. Run the command on every Pharos server that uses the plug-in. It does not propagate to other servers the way Pharos Administrator configuration does through Change Control.

  • Wider coverage of logon name formats in Kerberos mode. Account names, user principal names, user principal names using an alternate suffix, and the down-level DOMAIN\user form are all supported. In Kerberos mode the plug-in resolves the account in the directory first and builds the Kerberos principal from the account name and the Active Directory realm, so accounts whose user principal name suffix differs from the domain name authenticate correctly.

  • Improved diagnostics. --list-servers now reports the active authentication mode. Trace output states the mode up front, and in Kerberos mode reports the principal used, the KDC contacted, and a specific failure reason where one applies, such as an unreachable KDC, clock skew, an unknown principal, or a realm mismatch. Failure text written to the result file is prefixed with the mode attempted.

Existing setup commands are unchanged. --add-server, --drop-server and --clear-servers behave as they always have, and servers continue to be tried in priority order in both modes.

Switching to Kerberos

On each Pharos server that uses the plug-in:

adldaplogon --auth-mode kerberos
adldaplogon --list-servers

Use --list-servers to confirm the change took effect. If you need to go back, adldaplogon --auth-mode ntlm restores the previous behaviour.

Selecting Kerberos mode does not by itself prevent Windows from falling back to NTLM. To confirm that authentication is genuinely working over Kerberos, test with NTLM disabled on the machine. Kerberos also has requirements that NTLM does not, notably that directory servers are addressed by name rather than by IP address, that a Key Distribution Center is reachable, and that system clocks are in step with the domain.

Action may be required. For guidance on determining whether your site is affected, and for the recommended migration and testing procedure, refer to the Preparing Uniprint for NTLM Disablement Technote. Full reference information for the plug-in, including its registry configuration and complete command line, is in the Authenticating against an Active Directory System topic of the Uniprint help.

For details on all improvements and bug fixes, please see the 9.2 Release Notes information in the Pharos Help Center.