[24962] in Kerberos
Re: Cross-realm network traffic...
daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Thu Nov 17 16:35:42 2005
From: Jeffrey Altman <jaltman2@nyc.rr.com>
Message-ID: <7j6ff.10933$ek6.10474@news-wrt-01.rdc-nyc.rr.com>
Date: Thu, 17 Nov 2005 21:08:19 GMT
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Jiva DeVoe wrote:
> In the case of cross-realm authentication (ie: user@REALM1.COM
> authenticating to service/foo@REALM2.COM) does any traffic pass between
> either the respective KDCs or does the user@REALM1.COM client need to
> contact the KDC in REALM2?
>
> The context of the question is: if I have one or the other of the two
> realms behind a firewall, do I need to open any additional ports besides
> the traffic port for my service in order to support kerberos
> authentication?
>
> (This is of course assuming the cross-realm principals are configured
> appropriately in each realm.)
The client talks to a KDC in each realm in order to obtain the
TGTs for each realm. KDCs from different realms do not talk to one
another.
Firewalls should not block port 88/udp or 88/tcp. Otherwise, clients
cannot obtain tickets.
Jeffrey Altman
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos