Re: Query regarding S4U2Self protocol extension
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.general |
|---|---|
| Message-ID | <CAC-fF8RhhW2hUm28K4fXMbp-y4_ykkeZQyQFJvQn+AZa__zrBQ@mail.gmail.com> |
On Wed, Jul 28, 2021 at 11:10 AM Vipul Mehta <[email protected]> wrote: > > I have windows server 2012 R2 with all the security updates installed and did some tests: > > Resource Based Constrained Delegation configured for Service A in Service B account. > > Case 1) Service A : trustedToAuthForDelegation = false and non-empty msds-AllowedToDelegateTo -> S42U2Self ticket didn't have a forwardable flag and subsequent S4U2Proxy failed. That's expected because the default of 'NonForwardableDelegation' is enabled I think, so RBCD requires forwardable flag now, if you set NonForwardableDelegation to disabled (that is to 1 ..), then RBCD S4U2Proxy will continue to work as before the update. ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos