[22625] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos behind load balancer?

daemon@ATHENA.MIT.EDU (Jason T Hardy)
Wed Oct 6 08:17:12 2004

From: Jason T Hardy <jthardy@uta.edu>
To: Ken Raeburn <raeburn@mit.edu>
In-Reply-To: <B3E99E41-174C-11D9-8393-000A95909EE2@mit.edu>
Content-Type: text/plain
Message-Id: <1097064633.3297.4.camel@dionysus.uta.edu>
Mime-Version: 1.0
Date: Wed, 06 Oct 2004 07:13:48 -0500
Content-Transfer-Encoding: 7bit
cc: "'kerberos@mit.edu'" <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu

On Tue, 2004-10-05 at 23:03, Ken Raeburn wrote:
> I think there are better solutions to that.  (1) Create a DNS name 
> which points to multiple addresses; typically the nameserver will 
> change the order randomly, which will effect some load balancing.  (2) 
> Use DNS SRV records to return the names of the various KDCs, with equal 
> priority.  Granted, these approaches aren't load-sensitive, but the DNS 
> SRV record approach will let you do some uneven load balancing by 
> adjusting the weights based on the capabilities of each server.  
> They'll also let you spread out your KDCs to a couple of locations, if 
> you don't want to risk a single point of failure.

This is precisely what I * can not * do for political reasons.

-- 
Jason T Hardy
Unix Systems Administrator
Office of Information Technology
University of Texas at Arlington

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post