Re: Kerberos proxy for implementing referrals
- From: deengert@xxxxxxx ("Douglas E. Engert")
- Date: Wed, 24 May 2006 13:08:38 -0500
Before you do this, you may want to look at "Trusted Domain Ojests"
and "Globus Catalog" There may be a way to use the "netdom" command to:
"Establish one-way or two-way trust relationships between domains,
including the following kinds of trust relationships:
...
The Windows Server 2003 or Windows 2000 Server half of an
interoperable Kerberos realm."
Google for netdom, trusted domain object or TDO, referral and cross realm
or Google for "Domain and Forest Trust Tools and Settings"
( I have not tried this. But it looks like the netdom command could
setup the TDO that is missing.)
Richard E. Silverman wrote:
I'm considering the use of a Kerberos proxy, to solve the problem of being
unable to do cross realm authentication though a Windows realm to an MIT
one, due to Windows not issuing referrals for external realms. The proxy
would issue referrals where needed instead of having the Windows KDC say
"no such principal," and send/return all other requests to Windows for the
client. Obviously, the proxy will need the TGS keys for the Windows
realm. This is a last resort; I'm going mad badgering Microsoft for some
sort of solution to this. My outstanding request to them is whether they
can issue default referrals. I'm not expecting a positive answer.
I'm wondering whether anyone else has considered this, or (hoping against
hope), already implemented it?
I've considered using the KfW GSSAPI library with clients that support it
(Firefox, SecureCRT, etc.), but this is probably not a workable option for
us.
All comments welcome and appreciated,
--
Douglas E. Engert <DEEngert@xxxxxxx>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos
.
- Follow-Ups:
- Re: Kerberos proxy for implementing referrals
- From: Richard Silverman
- Re: Kerberos proxy for implementing referrals
- References:
- Kerberos proxy for implementing referrals
- From: Richard E. Silverman
- Kerberos proxy for implementing referrals
- Prev by Date: Kerberos proxy for implementing referrals
- Next by Date: Re: Kerberos proxy for implementing referrals
- Previous by thread: Kerberos proxy for implementing referrals
- Next by thread: Re: Kerberos proxy for implementing referrals
- Index(es):
Relevant Pages
|
Loading