[24917] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos referrals

daemon@ATHENA.MIT.EDU (Josh Howlett)
Thu Nov 10 02:05:03 2005

Message-ID: <43726352.4070700@bristol.ac.uk>
Date: Wed, 09 Nov 2005 21:00:02 +0000
From: Josh Howlett <josh.howlett@bristol.ac.uk>
MIME-Version: 1.0
To: Kevin Coffman <kwc@citi.umich.edu>
In-Reply-To: <4d569c330511091236m9854338kf11e0b6cabf5b61@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: "Douglas E. Engert" <deengert@anl.gov>
Errors-To: kerberos-bounces@mit.edu

Kevin Coffman wrote:
> We started with a patch that assumed all referrals would go to one place.
> 
> We had a need to send referrals to either a test Windows forest or a
> production forest.  That is where the [domain_referral] stuff came
> from.  Then we found that some requests were coming in without
> fully-qualified names, and therefore we could not determine the
> "right" place for the referral.  For those requests, we send the
> referral to the default place, which in our case is to the production
> forest.

Kevin,

Do you think it would be possible to introduce an MIT KDC into an 
existing AD environment, such that W2K clients in the AD realm (if 
making a request for an unknown principal) can get referred to the MIT 
KDC's "default" place?

Many thanks, josh.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post