Cross Realm AD<->MIT Trust, with realm name clash?
Enrico M. V. Fasanelli
Enrico.M.V.Fasanelli at le.infn.it
Fri Feb 3 03:17:42 EST 2006
Jeffrey Altman wrote:
> Colin Simpson wrote:
...omissis...
>> Colin
>
> The two realms cannot communicate with one another because if you
> attempted to create a path by name from one to the other, the KDCs
> in each realm would think it was trying to talk to itself.
>
> If it is necessary for these realms to have cross realm relationships
> with any other realms in common or with each other, then one of the
> realms must change its name. There is no procedure for changing the
> name of a realm hosted by a MIT KDC. However, there is such a procedure
> for Windows 2003 Active Directory. It is extremely painful but it is
> possible.
Hi Jeff,
any pointer to the documentation on how to do this?
Ciao,
Enrico
>
> Jeffrey Altman
> Secure Endpoints Inc.
> ________________________________________________
> Kerberos mailing list Kerberos at mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
More information about the Kerberos
mailing list