Re: cross-realm delegation via attempted RBCD fails with KRB5KRB_AP_ERR_ILL_CR_TKT

2022-08-04 Thread Jacob Shivers
Hello, Reaching out again. Requesting any further input. As I have said, if something is poorly worded or requires further clarification I will be happy to elaborate and reword as necessary. Regards, On Wed, Apr 27, 2022 at 4:19 PM Jacob Shivers wrote: > > Sending this to the dev list to hope

can realms get "aliased" when there is a one-way trust? or, what is going on here?

2022-08-04 Thread Jerry Shipman
Hello, This might just be a microsoft implementation thing -- sorry. But I am scratching my head and wonder if somebody can help me understand what is going on. We have several different realms (both MIT KDCs and AD DCs) run by various departments. There are sometimes cross-realm trusts in one or

Re: can realms get "aliased" when there is a one-way trust? or, what is going on here?

2022-08-04 Thread Greg Hudson
On 8/4/22 13:18, Jerry Shipman wrote: > It seems that when a user tries to get a service ticket for the > afs/mit.foo.cornell@foo.cornell.edu (which doesn't exist), he will > wind up with two tickets, one for > afs/mit.foo.cornell@foo.cornell.edu and one for > afs/mit.foo.cornell@mit.fo