Click here to get back home

Kerberos authentication failed across forest

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Kerberos authentication failed across forest eltonchew 03-23-2006
Posted by eltonchew on March 23, 2006, 8:58 am
Please log in for more thread options
Hi community,

I have 2 domains each belonging to their respective forest and a one
way trust, as depicted below:
apple.one.com <- orange.two.com (orange trust apple)

Users from orange signon to their workstation using smartcard installed
with certificate using UPN of user@one.com (instead of
user@apple.one.com).

When we try to acheive Kerberos pass-through authentication to
resources in orange.two.com domain, say a Terminal Server, using
netmon, we discover that a Kerberos ticket cannot be retrieved because
the UPN passed to orange.two.com was user@one.com and it reported that
the client object cannot be found.

However, when a user signon to their workstation using user id /
password /domain, and try to acheive Kerberos pass-through
authentication to resources in orange.two.com domain, the ticket can
now be retrieved.

I wish to check with the community if there is anyway, by not changing
the UPN of user's smartcard, to workaround the problem of not being
able to retrieve a Kerberos ticket?

Many Thanks!


Similar ThreadsPosted
Kerberos authentication failed across forest March 23, 2006, 9:08 am
Kerberos machine authentication - apparent authentication failures May 30, 2005, 10:35 am
Insufficient rights to edit all GPOs in local forest from account in trusted forest. August 15, 2006, 1:21 pm
Windows 2003 Pre-authentication failed April 24, 2007, 5:05 pm
Pre-Authentication Failed - Type 0x0 - Code 0x19 - Event ID 675 June 4, 2008, 3:53 pm
How to set up Kerberos authentication? (some code :) August 18, 2005, 2:55 pm
Problems With Kerberos Authentication September 25, 2007, 2:33 am
Kerberos and Integrated Windows authentication July 24, 2005, 8:26 am
Kerberos V5 Authentication for a Telnet Session October 27, 2005, 3:21 am
Intermittent Kerberos authentication failure June 14, 2007, 2:26 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap