Trying to implement Kerberos Constrained delegation in AD SSO but know nothing about AS400 stewie055

​Hello, I work in a security team at my company. I’ve been tasked to do something about the 40 AD service accounts that have been created for AS400/AD SSO. They are ALL in unconstrained delegation which drives me crazy. Basically, it means that anyone who controls the sso server can impersonate AS400 users. The two guys managing those AS400 have no time to spare on this project and they don’t want to tell me if it’s even possible to achieve RBCD or constrained delegation (kudos to them if they are in this sub) Is there any documentation somewhere that would argue in my favor ? Is it hard to setup ? Any help would be greatly appreciated submitted by /u/stewie055[link][comments] Read More 

IBM i at 35: A Community Celebration and Collaboration About the author

​Join Ian Jarman, CTO of IBM Expert Labs, in one of three worldwide webinar events on June 21, as he engages with a panel of IBM i luminaries, influencers and users to reflect on the achievements of the community and discuss the future of the platform.
This interactive e-book will feature contributions and insights from IBM i luminaries, partner innovators, IBM Power Systems Champions, educators, TechChannel Rising Stars and IBM i user groups. Read More 

Verified by MonsterInsights