[cifs-protocol] MS-KILE | TGT Delegation in external trusts

Isaac Boukris iboukris at gmail.com
Thu Feb 6 21:29:20 UTC 2020


Hello dochelp,

Yet another question on tgt-delegation. As far as I can tell from
tests and reading, tgt-delegation does not occur in external trusts,
even after successfully setting ENABLE_TGT using netdom command (that
is the cross-tgt does not have ok-as-delegate flag).

Can you confirm that ok-as-delegate is only set in forest trust, and
if so in MS-KILE 3.3.5.7.5, should the KDC also check for
FOREST_TRANSITIVE in trust-attributes in addition to ENABLE_TGT ?

Thank you



More information about the cifs-protocol mailing list