Kerberos Delegation

From: manukahn (manukahn.10somr_at_mail.mcse.ms)
Date: 01/29/04


Date: Thu, 29 Jan 2004 07:03:32 -0600


Hi

I would like to know if Kerberos Delegation is possible in a multi Hop
scenario.
For example: Is the following scenario possible?

A Client C Transfer its {TGT} to server "S" for Delegation, Server S
will FORWARD this {TGT} to server T for delegation again, (Second Hop).

Server T will finally ask for a ticket form service server Q to be able
to call that service in client's C name.

The question is: Is it possible for the Kerberos delegation algorithm
to run through multiple Hops?

I have read about Kerberos and found many explanations about Delegation
but ALL described Only one hop scenario.

Does this mean that Multi Hop Scenario is not possible?

Is there an article and example showing this?

Thanks

Emmanuel Kahn
Ecy1@bezeqint.net

manukahn
------------------------------------------------------------------------
Posted via http://www.mcse.ms
------------------------------------------------------------------------
View this thread: http://www.mcse.ms/message341311.html

 



Relevant Pages

  • Re: CreateDirectory working inconsistantly from ASP.net
    ... Many thanks Scott. ... Is there any way to test Delegation is functioning? ... > You are facing the dreaded double hop NTLM issue. ... When the browser authenticates to the web server from a remote ...
    (microsoft.public.dotnet.general)
  • Re: CreateDirectory working inconsistantly from ASP.net
    ... Many thanks Scott. ... Is there any way to test Delegation is functioning? ... > You are facing the dreaded double hop NTLM issue. ... When the browser authenticates to the web server from a remote ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: CreateDirectory working inconsistantly from ASP.net
    ... Many thanks Scott. ... Is there any way to test Delegation is functioning? ... > You are facing the dreaded double hop NTLM issue. ... When the browser authenticates to the web server from a remote ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Fixed Impersonation vs Current login user
    ... I also do think it is "double hop" issue, ... > which isn't sufficient to construct a new HTTP request passing credentials. ... > I think you'll need to configure delegation. ... Configure Computer Accounts and User Accounts So That They Are ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: OT: Wildepad
    ... I pose a scenario and ask a question within that framework. ... Rather than answering the question, someone gives their shallow, ... knee-jerk reaction to an aspect of the scenario, ... None of us are required to hop when you say hop. ...
    (rec.arts.sf.science)