<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client NAC Windows 7 using SSO AD with Active Directory 2003 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399876#M740086</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My client runs 3 AD in their environment with OS windows 2003. Now they plan to upgrade one AD to windows 2008,&lt;/P&gt;&lt;P&gt;but the "function level" is still windows 2003. When I ran ktpass in 2008, there will be some error messages appear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested NAC with pure windows 2008 and it works fine with AD SSO.&lt;/P&gt;&lt;P&gt;But some customer won't upgrade AD straight to pure wondows 2008 in case of some incompatible problems.&lt;/P&gt;&lt;P&gt;So is there any method to solve the environment with Server 2008 but function level is still Server 2003?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps: According to the document "If the AD system is based on an upgrade from Windows Server 2003, you must raise the domain functionality to Windows Server 2008 level for Cisco NAC appliance to perform SSO on &lt;STRONG&gt;Windows 7 clients&lt;/STRONG&gt;. Without this you will not be able to automatically login to the Cisco NAC Appliance network.",&lt;SPAN style="text-decoration: underline;"&gt; if the client's PC OS is &lt;STRONG&gt;XP&lt;/STRONG&gt;, not windows 7, will it not be affected with AD SSO??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Apr 2010 07:48:23 GMT</pubDate>
    <dc:creator>jetli1983</dc:creator>
    <dc:date>2010-04-27T07:48:23Z</dc:date>
    <item>
      <title>Client NAC Windows 7 using SSO AD with Active Directory 2003/2008</title>
      <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399872#M740019</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question, can i integrate NAC 4.7.2 with AD 2K3 using client machine windows 7 to login with SSO?, I have this question, because I have client machines in windows 7 and I have integrated NAC 4.7.2 with AD 2K8 to SSO, but I havent raised funtional level from W2K3 to W2K8, but it works client machine WXP with SSO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggest?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 07:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399872#M740019</guid>
      <dc:creator>Alvaro Perez Unzueta</dc:creator>
      <dc:date>2020-02-22T07:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Client NAC Windows 7 using SSO AD with Active Directory 2003</title>
      <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399873#M740025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alvaro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Raise the domain level to 2k8. That's the only supported method that works with SSO. More details here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://bit.ly/471_SSO"&gt;http://bit.ly/471_SSO&lt;/A&gt;&lt;SPAN&gt; footnote 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Apr 2010 19:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399873#M740025</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-04-21T19:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Client NAC Windows 7 using SSO AD with Active Directory 2003</title>
      <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399874#M740045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it works AD2K3 + NAC 4.7.2 + Windows 7 client + SSO AD? i undertand that i have to enable DES encryption, but one time done that it is work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alvaro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Apr 2010 20:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399874#M740045</guid>
      <dc:creator>Alvaro Perez Unzueta</dc:creator>
      <dc:date>2010-04-21T20:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Client NAC Windows 7 using SSO AD with Active Directory 2003</title>
      <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399875#M740061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alvaro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. That can work, but you have to create a new account and run ktpass on it differently. Make sure the KTPASS version is the one ending in 1830 and run it like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN&gt;KTPASS.EXE -princ newadsso/[adserver.]&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:domain.com@DOMAIN.COM"&gt;domain.com@DOMAIN.COM&lt;/A&gt;&lt;SPAN&gt; -mapuser newadsso -pass &lt;/SPAN&gt;&lt;BR /&gt;PasswordText -out c:\newadsso.keytab -ptype KRB5_NT_PRINCIPAL&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN&gt;More info: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://bit.ly/471_SSO"&gt;http://bit.ly/471_SSO&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Faisal&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Apr 2010 22:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399875#M740061</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-04-22T22:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Client NAC Windows 7 using SSO AD with Active Directory 2003</title>
      <link>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399876#M740086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My client runs 3 AD in their environment with OS windows 2003. Now they plan to upgrade one AD to windows 2008,&lt;/P&gt;&lt;P&gt;but the "function level" is still windows 2003. When I ran ktpass in 2008, there will be some error messages appear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested NAC with pure windows 2008 and it works fine with AD SSO.&lt;/P&gt;&lt;P&gt;But some customer won't upgrade AD straight to pure wondows 2008 in case of some incompatible problems.&lt;/P&gt;&lt;P&gt;So is there any method to solve the environment with Server 2008 but function level is still Server 2003?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps: According to the document "If the AD system is based on an upgrade from Windows Server 2003, you must raise the domain functionality to Windows Server 2008 level for Cisco NAC appliance to perform SSO on &lt;STRONG&gt;Windows 7 clients&lt;/STRONG&gt;. Without this you will not be able to automatically login to the Cisco NAC Appliance network.",&lt;SPAN style="text-decoration: underline;"&gt; if the client's PC OS is &lt;STRONG&gt;XP&lt;/STRONG&gt;, not windows 7, will it not be affected with AD SSO??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Apr 2010 07:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-nac-windows-7-using-sso-ad-with-active-directory-2003/m-p/1399876#M740086</guid>
      <dc:creator>jetli1983</dc:creator>
      <dc:date>2010-04-27T07:48:23Z</dc:date>
    </item>
  </channel>
</rss>

