Managing Multiple Realms

Hierarchical Interrealm Trust

These actions are described in detail in the following sections. The example configuration in this section uses the interrealm authentication principals shown in Figure 10-1.

Figure 10-1 Hierarchical Interrealm Configuration

The relationships are defined as follows:

krbtgt/BAMBI.COM@FINANCE.JUNGLE.COM allows the server in

BAMBI.COM to accept tickets from FINANCE.JUNGLE.COM.

krbtgt/IT.JUNGLE.COM@BAMBI.COM allows the server in IT.JUNGLE.COM to accept tickets from BAMBI.COM.

Chapter 10

283