Microsoft has introduced Kerberos Constrained Delegation (KCD) with Windows Server 2003, which is the technology behind Back-side Kerberos SSO. With Windows Server 2012 KCD has been enhanced with Resource-Based Kerberos Constrained Delegation (RBKCD). With standard KCD users can only be impersonated within the same domain while RBKCD allows doing KCD across domain boundaries.
How standard KCD can be configured with Airlock Gateway is described in this chapter.