[krbwg-51] [grand.central.org #274] Re: Consider keeping name referal
John Brezak via RT
rt-krbwg-51@grand.central.org
Wed, 16 May 2001 18:25:37 -0400 (EDT)
<URL: http://new-grand.central.org//rt//Ticket/Display.html?id=274 >
[hartmans - Sun May 13 17:47:51 2001]:
>
> So, I think what we want to do is send to the main working group list
> and make sure they are OK adding back in the realm referals stuff. I
> don't expect any problems, but we should still confirm we have a
> consensus to do this.
>
I'll post a message to the krb-wg list openning a discussion on this
part:
c) TGS referrals - the scenario is that you want to remove extensive
realm binding information from the client configuration. This means
that a TGS request to a realm that does not have that service can
return a referral to a "closer" realm. The change is that instead of
a server returning a service principal unknown error, it will return
an
(unsolicited) cross-realm ticket to a "closer" realm. This saves the
client from having to know the realm of the server beforehand. It
was agreed that this is very useful and should be part of kerberos-
revisions.
--