Re: Kerberos Database Sync with Sub-Domains
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.general |
|---|---|
| Message-ID | <CAC-fF8R9BSmW8MokUxt3ybGB0ANG9iUNQarbf17jTx4y3TJzRA@mail.gmail.com> |
On Tue, Jul 14, 2020 at 3:22 PM Jonathan Towles <[email protected]> wrote: > > So by using enterprise principal names, you can essentially point it at the parent domain KDC, and it can get a ticket for even users in the sub-domains? Client-referrals are used to locate the realm, see details in RFC 6806. > That's only something that can be done in the GSS config right? You can't do it in the KRB5.conf file? For kinit, you just need to pass the '-E' flag, no conf involved. ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos