[24961] in Kerberos

home help back first fref pref prev next nref lref last post

Cross-realm network traffic...

daemon@ATHENA.MIT.EDU (Jiva DeVoe)
Thu Nov 17 14:31:56 2005

Mime-Version: 1.0 (Apple Message framework v746.2)
To: kerberos@mit.edu
Message-Id: <065CAE4F-E4D9-4C8D-BEBC-22825F014157@devoesquared.com>
From: Jiva DeVoe <jiva@devoesquared.com>
Date: Thu, 17 Nov 2005 10:54:52 -0500
Content-Type: multipart/mixed; boundary="===============23314679560240537=="
Errors-To: kerberos-bounces@mit.edu


--===============23314679560240537==
Content-Type: multipart/signed; micalg=sha1;
	boundary=Apple-Mail-39--683129458; protocol="application/pkcs7-signature"


--Apple-Mail-39--683129458
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=US-ASCII;
	delsp=yes;
	format=flowed

In the case of cross-realm authentication (ie: user@REALM1.COM  
authenticating to service/foo@REALM2.COM) does any traffic pass  
between either the respective KDCs or does the user@REALM1.COM client  
need to contact the KDC in REALM2?

The context of the question is: if I have one or the other of the two  
realms behind a firewall, do I need to open any additional ports  
besides the traffic port for my service in order to support kerberos  
authentication?

(This is of course assuming the cross-realm principals are configured  
appropriately in each realm.)
--Apple-Mail-39--683129458--

--===============23314679560240537==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============23314679560240537==--

home help back first fref pref prev next nref lref last post