Generating KDC Referrals to locate Kerberos realms

Document Type Expired Internet-Draft (individual)
Authors Michael Swift  , John Brezak  , Jonathan Trostle  , Kenneth Raeburn 
Last updated 1999-11-16
Stream (None)
Intended RFC status (None)
Expired & archived
plain text htmlized pdfized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


The draft documents a new method for a Kerberos Key Distribution Center (KDC) to respond to client requests for tickets as is used in Microsoft's Windows 2000 implementation of Kerberos. The KDC will handle requests for principals in other realms by returning either a referral error or a cross-realm TGT to another realm on the referral path.


Michael Swift (
John Brezak (
Jonathan Trostle (
Kenneth Raeburn (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)