Re: Query regarding S4U2Self protocol extension

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <CAC-fF8RhhW2hUm28K4fXMbp-y4_ykkeZQyQFJvQn+AZa__zrBQ@mail.gmail.com>
On Wed, Jul 28, 2021 at 11:10 AM Vipul Mehta <[email protected]> wrote:
>
> I have windows server 2012 R2 with all the security updates installed and did some tests:
>
> Resource Based Constrained Delegation configured for Service A in Service B account.
>
> Case 1) Service A :  trustedToAuthForDelegation = false and non-empty msds-AllowedToDelegateTo -> S42U2Self ticket didn't have a forwardable flag and subsequent S4U2Proxy failed.

That's expected because the default of 'NonForwardableDelegation' is
enabled I think, so RBCD requires forwardable flag now, if you set
NonForwardableDelegation to disabled (that is to 1 ..), then RBCD
S4U2Proxy will continue to work as before the update.
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.