12 April,16 at 11:24 AM
Question:
If there are multiple trusted domains, Centrify-Enabled Putty takes a long time to obtain a host ticket. How do I optimize this issue?
Answer:
By default, Centrify-Enabled Putty tries to get the host ticket on the logon domain (Realm) only.
If the host is not in the same realm as the user, the user can go to Putty's Kerberos tab and select "Find machine from trusted domains". Putty will try to get the host ticket from other trusted domains when this checkbox is selected.
This function is a requirement when the host is from another forest or from an external trusted domain.
To speed up the process, specify the service principal name in the Kerberos tab. This will instruct Centrify-Enabled PuTTY to talk to the specified KDC only.
The SPN should be like this:
host/yourmachine.yourdomain.com@YOURREALM