[38046] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Does MIT Kerberos KDC supports Constrained Delegation natively

daemon@ATHENA.MIT.EDU (Greg Hudson)
Wed Aug 2 11:09:03 2017

To: Yu Yu <twonlyu@gmail.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <2936db92-d141-4e72-9db8-8b71b59b03ce@mit.edu>
Date: Wed, 2 Aug 2017 11:08:51 -0400
MIME-Version: 1.0
In-Reply-To: <CAAKRdSB01BKxcjLA1v9s8ZGkV7twRWxPL0Lo2N14ptuT8jT7KQ@mail.gmail.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On 08/02/2017 07:43 AM, Yu Yu wrote:
> Might I ask if MIT Kerberos KDC supports Constrained Delegation (S4U2Self
> and S4U2Proxy) feature natively, or if additional back-end (for example,
> LDAP) required for it?

The LDAP KDB module (which is still technically "native") is required to
configure constrained delegation permissions in the KDC.

One configures them by setting "krbAllowedToDelegateTo" attribute values
on the intermediate principal LDAP entry, where each value is an allowed
target service principal name.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post