Windows 8.1 cannot manage Windows credentials when joined to Samba 4.1 NT-style domain
This document (7016786) is provided subject to the disclaimer at the end of this document.
Environment
SUSE Linux Enterprise Server 12
Situation
Using a Windows 8.1 client that has been updated with the Windows Security update KB2992611 or KB3000850 which has also been joined to an NT-Style domain, the customer is not able to use the Windows Credential Manager application.
This would include for example, a SLES Samba NT-Style PDC.
When they attempt to use the Windows Credential Manager application they get the following error: Error code: 0x80090345 Error Message: The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation. This error doesn't occur with a system that is not part of this NT-Style domain.
It also does not occur if the workstation has not had Windows Security Update KB2992611 or KB3000850 applied even though it is part of the NT-Style domain.
Resolution
This is a known issue for Microsoft.
In this Microsoft document you will find their suggested workaround.
https://support.microsoft.com/en-us/kb/3000850
Here is some of the information from that document.
Workaround To work around this problem, set the value of the ProtectionPolicy registry entry to 1 to enable local backup of the MasterKey instead of requiring a RWDC in the following registry subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb Based in that information, it is obvious that this would need to be done on each Windows 8.1 client that has been updated with KB2992611 or KB3000850.
Cause
Additional Information
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7016786
- Creation Date: 20-Aug-2015
- Modified Date:03-Mar-2020
-
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com