Constrained Delegation using s4u2Self and S4u2Proxy

2016-09-26 Thread Tapas Sharma
Hi Krb Dev's, I am writing a proxy for SQL Server, where in I want to also authenticate the clients that want to connect using Kerberos. The proxy server sits in between the client and the sql server, and authenticates requests of the following types currently 1.NTLM 2. SQL Authentication. The AP

Re: Using enterprise principal name in GSS-API

2016-09-26 Thread Greg Hudson
On 09/25/2016 04:32 PM, Isaac Boukris wrote: > The more a look at the code and on wire traffic, I think > enterprise-name and canonicalization are different things (although > related). > Here is what my tests against AD (w2k3) seem to show so far. > > First, the 'kinit' man page says -E implies -