I know in a Windows environment local passwords are stored in SAM and domain passwords are cached locally in the register at HKEY_LOCAL_MACHINE\SECURITY\CACHE\NL$1 through NL$10.

At the moment I am doing an password audit on a Novell server
(NDS/ eDirectory) and Windows client environment. In this case local passwords are still stored in SAM. But where are the local NDS cached passwords on the Windows client. Probably not in the same register location, since I cannot grab them with CacheDump?

