[OpenAFS-devel] Win2k OpenAFS 1.1.1a WTS multiuser strangeness

Leif Johansson leifj@it.su.se
Fri, 7 Sep 2001 23:45:30 +0200


We have discovered a rather strange problem with base win2k (no
servicepacks) in a multiuser environment (RDP) with openafs 1.1.1a.
The setup is as follows:

- Windows 2000 Advanced Server with Terminal Server and OpenAFS 1.1.1a
- Domain controller is a samba box.
- Client is an X-windows RDP implementation (rdesktop) on Linux

The problem is that all users logged in on the terminal server seems to
share tokens. A typical scenario:

1. User A and B is logged in on the ts.
2. User A does klog to get tokens
3. User B does tokens and sees and can use user A's tokens
4. User B does unlog.
5. User A no longer has tokens.

However if you add SP2 everything seems to work (i.e no unexpected
sharing of tokens)! The transarc client does not exhibit this behaviour
regardless of servicepacks. 

Is this a well know fact? Don't get me wrong -- there is nothing wrong
with using SP2 but it would be nice to know why this happens.

	Cheers Leif