Creating a user account in the domain of the Authentication Server
This topic provides instructions for creating a user account for the Authentication Service in the domain (that is, the Kerberos realm) where the Authentication Server is running.
To create a user account for the Authentication Server
- On Microsoft Windows Server 2000 or 2003, select Start > Programs > Administrative Tools > Active Directory Users and Computers.
The Active Directory Users and Computers window appears. - In the left column, expand the domain name for the Authentication Server so that it displays the Users folder.
- Right-click the Users folder and select New > User.
The New Object - User wizard starts. - In First name, enter a name, such as blauthsvc and in User logon name, enter the name again. In this example, you would enter blauthsvc again.
- Click Next.
- In Password, set the password. Be sure to use a password that conforms to the Active Directory password policy.
- Select Password never expires.
- Click Next.
The summary page appears. - Click Finish.
- From the Active Directory Users and Computers window, do the following steps:
- Make sure the domain name for the Authentication Server is expanded so that it shows the Users folder in the left column.
- Click the Users folder, and then double-click the blauthsvc user in the right column.
The Properties window for that user appears. - Click the Account tab.
- Under Account Options, select Use DES encryption types for this account.
- Click OK.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*