configuring kerberose-sso-negotiate in multiple domains

Posted by and777 on Stack Overflow See other posts from Stack Overflow or by and777
Published on 2010-03-16T21:22:40Z Indexed on 2010/03/18 19:21 UTC
Read the original article Hit count: 350

Filed under:
|
|
|

hi all

I have mycorp.com, ch1.mycorp.com, mycorp2.com domains (it is all windows) I am configuring sso-kerberose-negotiate authentication My server running in mainaaa3.mycorp2.com, I have created spn "http:/mainaaa3.mycorp2.com" for it, and I have set trusts between domains, but if users from mycorp.com, ch1.mycorp.com domains that browser do not send negotiate-ticket, and then I have created spn in each domains for "http:/mainaaa3.mycorp2.com", and now I have error: Mechanism level: Integrity check on decrypted field failed (31)

what am I doing wrong?

© Stack Overflow or respective owner

Related posts about kerberos

Related posts about multiple