Kerberos Delegation

ecy1_at_bezeqint.net
Date: 01/29/04


Date: Thu, 29 Jan 2004 04:16:17 -0800

Hi

I would like to know if Kerberos Delegation is possible in
a multi Hop scenario.
For example: Is the following scenario possible?

A Client C Transfer its {TGT} to server "S" for
Delegation, Server S will FORWARD this {TGT} to server T
for delegation again, (Second Hop).
Server T will finally ask for a ticket form service server
Q to be able to call that service in client's C name.

The question is: Is it possible for the Kerberos
delegation algorithm to run through multiple Hops?

I have read about Kerberos and found many explanations
about Delegation but ALL described Only one hop scenario.

Does this mean that Multi Hop Scenario is not possible?

Is there an article and example showing this?

Thanks

Emmanuel Kahn
ecy1@bezeqint.net



Relevant Pages

  • Re: UNC Virtual Directories; NTFS permission authentication not ac
    ... If you want Kerberos delegation to work, you need to have everything setup correctly end-to-end. ... The browser must authenticate using Kerberos, which means that both IE must attempt Kerberos *and* the relevant server SPNs must be created/set correctly. ... > Windows Authentication option the ...
    (microsoft.public.inetserver.iis.security)
  • Re: Delegation through Linked Server Stops working
    ... "Troubleshooting Kerberos delation" is nearly a 90 page doc. ... you do when/if you open a ticket. ... This post was about delegation working and then suddenly ... delegation on linked server fails in our network when we use ...
    (microsoft.public.sqlserver.security)
  • Re: Delegation: IIS Server setup in typical 3-tier scenario.
    ... doesn't already have an SPN and/or you need to change the existing SPN. ... Kerberos is being used - it just means that an API is used to determine what ... so I'm trying to set up delegation. ... Authenticated using NTLM not Kerberos on the Web Server. ...
    (microsoft.public.inetserver.iis.security)
  • Kerberos Delegation
    ... Delegation, Server S will FORWARD this to server T ... Is it possible for the Kerberos ... about Delegation but ALL described Only one hop scenario. ...
    (microsoft.public.dotnet.security)
  • Re: EFS error: event id: 6203 on Windows Server 2003
    ... Trusted for delegation was not enabled, but that didn't solve my problem. ... encrypted on our old file server which is in the meantime switecd off. ... Also to encrypt files ... > are using NTLM authentication rather than Kerberos. ...
    (microsoft.public.win2000.security)