Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

You cannot log on to a Windows Server 2003 domain by using a user account after you reset the user account password by using the ktpass.exe tool together with the -pass * parameter


View products that this article applies to.

Symptoms

Consider the following scenario. You reset a user account password by using the Ktpass.exe tool together with the -pass * parameter. Then, you try to log on to a Microsoft Windows Server 2003 domain by using that user account. In this scenario, the logon attempt is unsuccessful. Additionally, you receive the following error message:
The system could not log you on. Make sure your User name and domain are correct, then type your password again. Letters in passwords must be typed using the correct case.

↑ Back to the top


Cause

When you use the -pass * parameter in the Ktpass.exe tool, the Ktpass.exe tool appends the following extra characters to the password:
\0a
The tool then sends the password to the Active Directory directory service. Therefore, Active Directory stores an incorrect password for this user account. And because the password is incorrect, you cannot log on to the Windows Server 2003 domain.

↑ Back to the top


Resolution

Hotfix information

A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing this specific problem. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site: Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.

Prerequisites

To apply this hotfix, you must have Windows Server 2003 Service Pack 1 or Windows Server 2003 Service Pack 2 installed on the computer.
889100� How to obtain the latest service pack for Windows Server 2003

Restart requirement

You do not have to restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace any other hotfixes.

File information

The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
Windows Server 2003 with Service Pack 1, x86 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatform
Ktpass.exe5.2.3790.297691,13617-Jul-200711:08x86
Windows Server 2003 with Service Pack 2, x86 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatform
Ktpass.exe5.2.3790.411991,13617-Jul-200712:14x86
Windows Server 2003, x64 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Ktpass.exe5.2.3790.2976145,92017-Jul-200705:33x64SP1Not Applicable
Wktpass.exe5.2.3790.297691,13617-Jul-200705:33x86SP1WOW
Windows Server 2003 with SP2, x64 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Ktpass.exe5.2.3790.4119145,92017-Jul-200705:38x64SP2Not Applicable
Wktpass.exe5.2.3790.411991,13617-Jul-200705:38x86SP2WOW
Windows Server 2003 with Service Pack 1, IA-64 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Ktpass.exe5.2.3790.2976320,51217-Jul-200705:33IA-64SP1Not Applicable
Wktpass.exe5.2.3790.297691,13617-Jul-200705:33x86SP1WOW
Windows Server 2003 with Service Pack 2, IA-64 version
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Ktpass.exe5.2.3790.4119320,51217-Jul-200705:37IA-64SP2Not Applicable
Wktpass.exe5.2.3790.411991,13617-Jul-200705:37x86SP2WOW

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

The Ktpass.exe tool is a command-line tool that lets an administrator configure a non-native Kerberos service as a security principal in the Windows Server 2003 Active Directory. The Ktpass.exe tool configures the server principal name for the host or for the service in Active Directory. This tool also generates an MIT-style Kerberos keytab file that contains the shared secret key of the service. The Ktpass.exe tool enables UNIX-based services that support Kerberos authentication to use the interoperability features that are provided by the Windows Server 2003 Kerberos KDC service.

In the Ktpass.exe tool, the -pass parameter is used to directly input a password. However, if you input the -pass * parameter, the placeholder characters (*) will be displayed, and then you will be prompted for a password.

↑ Back to the top


Keywords: KB939980, kbexpertiseinter, kbqfe, kbhotfixserver, kbautohotfix

↑ Back to the top

Article Info
Article ID : 939980
Revision : 5
Created on : 10/11/2007
Published on : 10/11/2007
Exists online : False
Views : 279