Inter-realm
Configuring Direct Trust Relationships
The Kerberos Server returns a failure for any of the following reasons:
•If the client authentication fails.
•It does not recognize the realm listed in the
•It does not recognize the requested service principal, and has no further trust relationships for which it returns an
Direct Trust Relationship Example
To set up a
krbtgt/ADMIN.BAMBI.COM@IT.BAMBI.COM
krbtgt/IT.BAMBI.COM@ADMIN.BAMBI.COM
The above special principal indicates a
krbtgt/ADMIN.BAMBI.COM@IT.BAMBI.COM
The passwords of the corresponding principals has to be the same on both the KDCs. But, the different
For example,
krbtgt/ADMIN.BAMBI.COM@IT.BAMBI.COM has to have the same password on each KDC, but
krbtgt/IT.BAMBI.COM@ADMIN.BAMBI.COM and krbtgt/ADMIN.BAMBI.COM@IT.BAMBI.COM do not have to share the same password.
Chapter 8 | 251 |