[22742] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Cross realm auth with MS Server 2003 and MIT kerb

daemon@ATHENA.MIT.EDU (BarBaar)
Mon Oct 25 13:13:20 2004

From: beurdy@priest.com (BarBaar)
Date: 25 Oct 2004 06:21:05 -0700
Message-ID: <b87356fd.0410250521.742f3c67@posting.google.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Hello,

Today I started to sniff the network, while trying to setup aan
cross-realm kerberos-session... (realm named: test.nl and
tester.test.nl)

And the sniffer (ethereal) did not tell me very much.. But he did tell
me the WinXp client is requesting a TGS from the w2k3 AD KDC (which is
good!). And the AD KDC send a error back:
krb5kdc_err_s_principal_unknown.. (which is not good)

So (correct me if I am wrong) the AD KDC does not see that this host
is in a different realm, and therefore does not respond with the
correct ticket (which should be a krbtgt/TEST.NL@TESTER.TEST.NL?)

Any ideas on this?
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post