<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://adopenstatic.com/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx</link><description>In this part we extend, slightly, upon the previous scenario , by adding delegation. Now we need to allow IIS, in our resource Forest (or domain) to delegate the end user&amp;rsquo;s credentials, to a backend service (SQL Server in this case): The machines</description><dc:language>en</dc:language><generator>CommunityServer 2.1 (Build: 60809.935)</generator><item><title>Kerberos przyjacielem mym</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#17879</link><pubDate>Fri, 11 Jul 2008 12:49:54 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:17879</guid><dc:creator>.neting in the free world</dc:creator><description>&lt;p&gt;Coraz częściej w pracy stykam się z koniecznością ustawienia autentykacji poprzez protok&amp;#243;ł Kerberos ,&lt;/p&gt;
</description></item><item><title>Kerberos przyjacielem twym</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#17883</link><pubDate>Fri, 11 Jul 2008 13:21:38 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:17883</guid><dc:creator>.neting in the free world</dc:creator><description>&lt;p&gt;Coraz częściej w pracy stykam się z koniecznością ustawienia autentykacji poprzez protok&amp;#243;ł Kerberos ,&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#18270</link><pubDate>Mon, 25 Aug 2008 16:42:44 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:18270</guid><dc:creator>Paul</dc:creator><description>Thank you Ken for "IIS and Kerberos" series - really helpful.

Is there any way to disable NTLM completely and authenticate using Kerberos only?

Thanks,
paul

</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#18515</link><pubDate>Sat, 20 Sep 2008 12:17:53 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:18515</guid><dc:creator>Ken</dc:creator><description>&lt;p&gt;Hi Paul,&lt;/p&gt;
&lt;p&gt;No - that's not possible.&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Ken&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#18953</link><pubDate>Tue, 28 Oct 2008 12:59:37 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:18953</guid><dc:creator>Saurabh </dc:creator><description>One word to express my gratitude would be fabulous.
I recently came to know about your article series on Kerberos and seeing the exhaustive coverage I really admire the great work you have done. I myself belong to IIS support group within MS which deals with troubleshooting on kerberos issues for our customers, and your articles look very valuable indeed.
Great work!</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#18955</link><pubDate>Tue, 28 Oct 2008 17:32:34 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:18955</guid><dc:creator>Steve Hall</dc:creator><description>Ken,

we have a MOSS environment and are planning out an integrated SQL reporting solution. The SQL reporting database is kept on a seperate clustered SQL instance. This configuration will exceed the double hop limit of NTLM. 

We currently have a cross-forest setup but only a one way trust. A two way trust will never be allowed. If kerberos requires a two way trust for delegation, and we can't have a two way trust, are we hosed? Are there any other solutions that will meet our needs?</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#19993</link><pubDate>Mon, 01 Dec 2008 04:02:45 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:19993</guid><dc:creator>rob</dc:creator><description>This is an A+ series of posts.
Having the captures downloadable to read along with kicks ass. Thanks for putting in the effort to do this.</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#20530</link><pubDate>Tue, 30 Dec 2008 01:14:14 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:20530</guid><dc:creator>chris</dc:creator><description>if i have users in forest A, and Resources (servers, and applications) in forest b.  and I run one of my applications as an user that resides in forest A.  There is a one way trust where Forest B trusts Forest B. Will i be able to use delegation in this scenario since both the service account that will be delegated to is in the same forest as the accounts being impersonated?  Or is it a hard rule that to use delegation where 2 forests are involved you HAVE to have a 2 way trust</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#21017</link><pubDate>Thu, 12 Feb 2009 04:50:06 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21017</guid><dc:creator>Ken</dc:creator><description>&lt;p&gt;Hi Chris,&lt;/p&gt;
&lt;p&gt;Sorry to take so long to get back to you. I'm not 100% sure about your situation. Will have to investigate and get back to you!&lt;/p&gt;
</description></item><item><title>IIS and Kerberos Part 9 - Cross Forest Delegation scenario with UPN suffix routing</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#21174</link><pubDate>Thu, 26 Feb 2009 12:24:33 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21174</guid><dc:creator>Ken Schaefer</dc:creator><description>&lt;p&gt;As an extension of the previous article on Cross Forest (or Cross Domain) Kerberos Authentication this&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#21250</link><pubDate>Mon, 02 Mar 2009 16:39:49 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21250</guid><dc:creator>Malcolm Gin</dc:creator><description>Ken,

In our environment, we are working in a single forest but multiple domains.

Is a two-way trust required in this model? We seem to have indications that Kerberos constrained delegation is working properly for us even though we are using a one-way trust.

If/when we have conclusive proof, I'll try to come back and follow up.

Thanks,
M</description></item><item><title>Vidar's Musings ?? The mother lode for IIS, Kerberos and IWA information</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#21323</link><pubDate>Fri, 06 Mar 2009 09:55:13 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21323</guid><dc:creator>Vidar's Musings ?? The mother lode for IIS, Kerberos and IWA information</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.kongsli.net/nblog/2009/03/06/the-mother-lode-for-iis-kerberos-and-iwa-information/"&gt;http://www.kongsli.net/nblog/2009/03/06/the-mother-lode-for-iis-kerberos-and-iwa-information/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: IIS and Kerberos Part 8 - a simple cross Forest/Domain delegation scenario</title><link>http://adopenstatic.com/cs/blogs/ken/archive/2008/06/28/17805.aspx#21387</link><pubDate>Mon, 09 Mar 2009 09:21:12 GMT</pubDate><guid isPermaLink="false">e0e31441-78b9-4457-b9b0-6f7906e03e71:21387</guid><dc:creator>Ken</dc:creator><description>&lt;p&gt;Hi Malcom,&lt;/p&gt;
&lt;p&gt;You have configured one-way trust between two domains in the same Forest? (I know that this is insufficient across Forests - because I tried for several days to get that working :-))&lt;/p&gt;
&lt;p&gt;Can you tell us which domains your users and resources are in?&lt;/p&gt;
</description></item></channel></rss>