Cross Realm AD<->MIT Trust, with realm name clash?

Enrico M. V. Fasanelli Enrico.M.V.Fasanelli at le.infn.it
Fri Feb 3 03:17:42 EST 2006


Jeffrey Altman wrote:
> Colin Simpson wrote:

...omissis...

>> Colin
> 
> The two realms cannot communicate with one another because if you
> attempted to create a path by name from one to the other, the KDCs
> in each realm would think it was trying to talk to itself.
> 
> If it is necessary for these realms to have cross realm relationships
> with any other realms in common or with each other, then one of the
> realms must change its name.   There is no procedure for changing the
> name of a realm hosted by a MIT KDC.  However, there is such a procedure
> for Windows 2003 Active Directory.  It is extremely painful but it is
> possible.

Hi Jeff,

any pointer to the documentation on how to do this?

Ciao,
	Enrico
> 
> Jeffrey Altman
> Secure Endpoints Inc.
> ________________________________________________
> Kerberos mailing list           Kerberos at mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 


More information about the Kerberos mailing list