Joining a multiple realm AD environment

Chris Penney penney at
Sun May 20 14:57:21 EDT 2007

On 5/18/07, Markus Moeller <huaraz at> wrote:
> Not sure what you mean with "Do you still have to do this even if you add
> the system to AD via a "User" account?" ?
> You add the system to AD to be able to create a keytab which is used to
> verify  that you talk to the right kdc during user authentication.  It has
> nothing to do with the ability to login from LOC1.DOM.COM or LOC2.DOM.COM

Ok, thanks!  I appreciate your answering my questions.  The multiple
realm concept wasn't very clear to me not having done it previously.


More information about the Kerberos mailing list