Forcing ticket name for host on windows

garnett nicolas.greneche at gmail.com
Wed Jul 6 08:21:28 EDT 2011


Hi,

When you enable kerberos authentication against a UNIX KDC, you must
have a principal host/fqdn at DEFAULT_REALM in the KDC.

I would like to keep on using DEFAULT_REALM as the default realm
EXPECT for my host principals. Those host principals will be stored in
another realm (ie HOST.DEFAULT_REALM) with a cross realm between
DEFAULT_REALM and HOST.DEFAULT_REALM ?

Do you know how to force windows ask for host/fqdn at HOST.DEFAULT_REALM
(and no longer host/fqdn at DEFAULT_REALM) with keeping DEFAULT_REALM as
the default realm ?

Thanks,



More information about the Kerberos mailing list