No idea if this is the right place for this, hopefully I can get some good answers.
ÃÂ
Question: Can a client in a un-trusted domain get a Kerberos ticket for another domain and use this to access multiple resourced without having to type username andÃÂ password in repeatedly?ÃÂ
ÃÂ
Scenario:
ÃÂ
Domain A contains Server B and Server C.ÃÂ SPN's regsitered for each https/FQDN. Only ports 80 and 443 open to internet.
ÃÂ
Windows XP Client in DomainÃÂ X connects to Server B over internetÃÂ using https/FQDN with Internet Explorer.ÃÂ Enable Integrated Windows Authentication isÃÂ checked.ÃÂ Everything is OK until he/she moves to Server C and is required toÃÂ end credentialsÃÂ again - this is a major pain for our customer.
ÃÂ
There is no trust between domain A and domain B and never wi ...
Go to the complete details ...
Found interesting? Add this to: