using '@' character in principals

Stephen Ingram sbingram at gmail.com
Fri Feb 18 16:20:18 EST 2011


Is it possible to use an '@' character in a kerberos principal such
that the full principal would read something like
user at domain1.com@DOMAIN.COM? Note that domain1.com is in the
DOMAIN.COM realm. I've been able to successfully add a principal like
this by using a '\' before the '@'. However, kinit doesn't seem to
pass the information similarly such that I can obtain a tgt.

It seems like some large installations accomplish this, but perhaps
they are using some sort of filtering before passing it to kinit?

Steve



More information about the Kerberos mailing list