Re: Problem with different domain names
2009-07-02 09:44:17 GMT
Finally, problem is solved. It was much easier than it looks like first. 1st problem was, that with testing etc. unfortunately the service principal existed twice in ActiveDirectory. With ADSIEdit, it was easy to find the second entry. Then, for the problem with the different dns zone. In the dns server in the zone acme.com I placed a TXT record: Name: _kerberos Type: Text (TXT) Data: ADS.ACME.COM With this entry, the XP clients are able to "reroute" to the ads.acme.com dns zone / realm, find the KDC and got the ticket for the service principal. Again, thank you all very much for your support. Greetings Ivo Linder -----Ursprüngliche Nachricht----- Von: Atte Peltomäki [mailto:atte.peltomaki <at> f-secure.com] Gesendet: Mittwoch, 3. Juni 2009 09:38 An: Henry B. Hotz Cc: Ivo Linder; modauthkerb-help <at> lists.sourceforge.net Betreff: Re: [modauthkerb] Problem with different domain names On Tue, Jun 02, 2009 at 09:12:24AM -0700, Henry B. Hotz wrote: > The production web server, www.acme.com, needs a HTTP/www.acme.com <at> ACME.COM > service principal issued by the production AD for ACME.COM. > > VISTA has some new domain to realm mapping options, and you can put > similar stuff in the [domain_realm] section of a unix krb5.conf file.(Continue reading)
RSS Feed