[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: TGT forwarding when cross-realm auth?
Jeffrey Hutzelman wrote:
> On Monday, June 06, 2005 10:30:55 AM -0500 "Douglas E. Engert"
> <firstname.lastname@example.org> wrote:
>> Even if you had trust setup both ways it would not be allow a
>> a krbtgt/A@B to be issued using the krtgt/B@A this as it would violate
>> the cross-realm trust assumptions because the user is still me@A.
>> Realm A expects the user@A to use the krbtgt/A@A for services in in A.
> Note that this protection does not live entirely in realm B. A proper
> KDC for realm A will not honor a krbtgt/A@B ticket for me@A, even if the
> realm B KDC were to issue one.
Yes, That is what I thought I said.
Douglas E. Engert <DEEngert@anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439