[32544] in Kerberos

home help back first fref pref prev next nref lref last post

Establishing and verifying a trust between Unix MIT KDC and Windows

daemon@ATHENA.MIT.EDU (N K)
Tue Aug 3 18:18:52 2010

MIME-Version: 1.0
Date: Tue, 3 Aug 2010 15:18:47 -0700
Message-ID: <AANLkTi=4YNKSuezMxRqDkM+bMpDZz14VLaeWBS7kABj=@mail.gmail.com>
From: N K <nkaluskar@gmail.com>
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi all,

I followed the steps for a cross-realm setup between the MIT KDC and AD
according to O'reilly's Definitive Guide book:

- specifying KDC's using ksetup on the participating Windows machines

- creating principals krbtgt/domain@realm and krbtgt/realm@domain in the MIT
KDC

- creating a 2 way trust in the AD

- mapping an AD user to a user in the MIT KDC

However, when I try to logon to the Kerberos realm from a Windows machine
using the credentials of the MIT KDC user, I get an error that the system
could not log me on because the username or domain is incorrect.

Has anyone come across a similar problem before?

Thanks much in advance,

Nivedita.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post