I need to enable kerberos constrained delegation for a front-end computer in domain A to a back-end computer in domain B, different forests.
Client accounts are also in domain B.
Domain controllers in both domains are WS 2008 R2.
According to requirements here:
http://technet.microsoft.com/en-us/library/hh831477.aspx#BKMK_kerb_const_del_domains
- is it enough to just have one additional domain controller running WS 2012 in each domain ?
- do remaining WS 2008 R2 domain controllers need this hotfix
http://support.microsoft.com/kb/2665790 ?
Thanks.