Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

A memory leak occurs in the Lsass.exe process after you configure constrained delegation in Windows Server 2003


View products that this article applies to.

Symptoms

To forward Kerberos user credentials to other servers, you have configured a multiple-server environment for constrained delegation. A memory leak occurs in the Lsass.exe process on the back-end server.

↑ Back to the top


Cause

The Kerberos tickets are not freed when they should be. The Microsoft Windows Server 2003-based Kerberos client does not correctly handle reference counting in this scenario. Therefore, the Lsass.exe process eventually uses the maximum amount of physical memory in Windows Server 2003.

↑ Back to the top


Resolution

Service pack information

To resolve this problem, obtain the latest service pack for Windows Server 2003. For more information, click the following article number to view the article in the Microsoft Knowledge Base:
889100 How to obtain the latest service pack for Windows Server 2003

Hotfix information

A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing this specific problem. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site: Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.

Prerequisites

No prerequisites are required.

Restart requirement

You must restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace any other hotfixes.

File information

The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

Windows Server 2003, 32-bit versions

File nameFile versionFile sizeDateTimePlatformSP requirement
Kerberos.dll5.2.3790.417344,06404-Oct-200503:29x86None
Kerberos.dll5.2.3790.2540350,72004-Oct-200503:01x86SP1

Windows Server 2003, Itanium-based versions

File nameFile versionFile sizeDateTimePlatformSP requirement
Kerberos.dll5.2.3790.417907,26404-Oct-200503:41IA-64None
Wkerberos.dll5.2.3790.417344,06404-Oct-200503:41x86None
Kerberos.dll5.2.3790.2540963,07204-Oct-200503:41IA-64SP1
Wkerberos.dll5.2.3790.2540350,72004-Oct-200503:41x86SP1

Windows Server 2003, x64-based versions

File nameFile versionFile sizeDateTimePlatformSP requirement
Kerberos.dll5.2.3790.2540720,89604-Oct-200503:41x64SP1
Wkerberos.dll5.2.3790.2540350,72004-Oct-200503:41x86SP1

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. This problem was first corrected in Windows Server 2003 Service Pack 2.

↑ Back to the top


More information

The hotfix must be installed on all servers that are at the back-end of the constrained delegation "Single Sign-On" authentication chain. Usually, these back-end servers are application servers and not domain controllers.

For more information, click the following article number to view the article in the Microsoft Knowledge Base:
824684 Description of the standard terminology that is used to describe Microsoft software updates

↑ Back to the top


Keywords: kbautohotfix, kbwinserv2003sp2fix, kbqfe, kbHotfixServer, kbbug, kbfix, KB907524

↑ Back to the top

Article Info
Article ID : 907524
Revision : 3
Created on : 10/9/2011
Published on : 10/9/2011
Exists online : False
Views : 262