Re: Differentiate the ServiceTicket issued from Kinit vs PKinit

2015-05-30 Thread Dr. Greg Wettstein
On May 22, 11:03am, Aravind Jerubandi wrote: } Subject: Differentiate the ServiceTicket issued from Kinit vs PKinit > Hello, Hi, I hope your weekend is going well. > Today we use password based authentication (kinit). And we want to > introduce PKinit. But while validating ServiceTicket we would

Re: Multi-tenancy in MIT KDC

2015-05-30 Thread Todd Grayson
I would suggest reading this: http://web.mit.edu/kerberos/krb5-devel/doc/admin/realm_config.html A ream is a namespace that defines a database containing principals. logically REALM its separated from domain. In AD environments by default the domain and the realm are the same value with uppercas