RESOLUTION
A supported hotfix is now available from Microsoft, but it is only intended to correct the problem that this article describes. Apply it only to systems that are experiencing this specific problem.
To resolve this problem, contact Microsoft Product Support Services to obtain the hotfix. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site:
Note In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
NOTE: This fix is not included in any Windows NT Service Pack, nor is it included in the IAS SP6 rollup fix. Before you install this fix, you must install the IAS SP6 rollup fix; for more information, see the following article in the Microsoft Knowledge Base:
239864 Availability of Internet Authentication Service SP6 Rollup Hotfix
How to Install the Fix
In order to use this fix, you must install this software on the IAS servers, both primary and backup domain controllers, so that authentication still operates, even if the primary domain controller is offline for any reason.
Before you install CHAP support on any domain controller, create an Emergency Repair Disk (ERD) for the domain controller. You can use the ERD to recover the server in the event of a problem with the CHAP support software.
To apply this fix on domain controllers, perform the following steps:
- To install the fix, run the Iaspack.exe tool that is included with the fix.
- Run Regedt32.
- On the Window menu, click "HKEY_LOCAL_MACHINE on Local Machine".
- Find the System\CurrentControlSet\Control\Lsa\MD5-CHAP key, and
then double-click the Store Clear Text Passwords value.
- In the DWORD Editor dialog box, change the data value from 0 to 1, and then click OK. Note that the REG_DWORD value is displayed as 0x1.
- Quit Registry Editor.
- Restart the domain controller.