Previous Topic: Map Foreign RealmsNext Topic: Map Foreign Principal Names


Example: REALM mapping

In this example, a trust relationship is established between TRUSTWORTHY.CA.COM with MAJESTERIAL.CLIENT.COM with the label MAJESTY in the SDT.

On the local system, define the following:

TSS ADD(SDT) REALM(majesty)
    REALMNAME(‘/…/trustworthy.ca.com/krbtgt/majesterial.client.com’)
    PASSWORD(xylofone)
TSS ADD(SDT) REALM(trustyca)
    REALMNAME(‘/…/majesterial.client.com/krbtgt/trustworthy.ca.com’)
    PASSWORD(marimba)

On the foreign system, a set of parallel definitions is required so that each connection in the conversation maintains identical passwords:

TSS ADD(SDT) REALM(kingart)
    REALMNAME(‘/…/trustworthy.ca.com/krbtgt/majesterial.client.com’)
    PASSWORD(xylofone)
TSS ADD(SDT) REALM(troubador)
    REALMNAME(‘/…/majesterial.client.com/krbtgt/trustworthy.ca.com’)
    PASSWORD(marimba)

The REALM operands are labels of convenience and do not have to match between the two systems. However, the password for each trust relationship must be identical for identical REALMNAME specifications.