Lamar,
Each windows DC is a KDC, AS, and TGS with support for any Kerberos V5
client, just point the clients at your domain FQDN.
Answers to Frequently Asked Kerberos Questions
http://support.microsoft.com/support.../Q266/0/80.ASP
Guide to Kerberos 5 (krb5 1.0) Interoperability
http://www.microsoft.com/windows2000.../kerbsteps.asp
"Lamar Thomas" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> We are an IBM AS/400 (iSeries) shop and are running a Windows 2003 domain
> with active diretory and DNS. I know that Windows now uses Kerberos for
> authetication. What we would like to do is use Kerberso across our
network
> across all platforms.
>
> I know that there has to be a Key Distribution Cinter (KDC), Authentcation
> Server (AS) and a Ticket Granting Server (TGS). What I don't know is if
> Windows is already setup to be them. I have two (2) DCs on my network.
> Which one would be the KDC? The first one or the one with the FSMO roles?
>
> Anyone know if Windows 2003 can act as the KDC, AS, TGS for all of our
> platforms (IBM, Linux/UNIX and Windows)?
>
> Any what papers or KB papers? Thanks for any help.
>
>
> Lamar
>
>