|Posted by:||lobezno (lobez…@discussions.microsoft.com)|
|Date:||Wed, 24 Dec 2008|
I'm workin with kerberos tickets and Constrained delegation.
Is it viable that for an Explorer navigator to reuse a ticket kerberos that
has been negotiated (on behalf of another user) between an ISA Server and an
IIS Server, to call that IIS Server with that Authoritation?
It means: we have created a ticket kerberos inside ISA (custom webfilter),
this ticket is delegated to an IIS, and a SQL Server after (simple kerberos
constrained delegation), but in the response, there is no ticket returns to
the client (internet explorer). This is possible??