[22626] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos behind load balancer?

daemon@ATHENA.MIT.EDU (Jason T Hardy)
Wed Oct 6 08:18:30 2004

From: Jason T Hardy <jthardy@uta.edu>
To: Frank Cusack <fcusack@fcusack.com>
In-Reply-To: <x5y1xgcxvvm.fsf@mother.corp.google.com>
Content-Type: text/plain
Message-Id: <1097064796.3297.8.camel@dionysus.uta.edu>
Mime-Version: 1.0
Date: Wed, 06 Oct 2004 07:14:10 -0500
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

On Wed, 2004-10-06 at 00:23, Frank Cusack wrote:
> > balancer, have all of the KDC's share one hostname. Our kadmin server
> > can also share that hostname.
> >
> >  kerberos:88 -> points to our KDC's
> >  kerberos:749 -> point to our admin server
> 
> Isn't that broken?  You can't load balance the admin server because
> MIT isn't multi-master.  For DR it's just as easy to bring up a new
> server with the old server's IP.

No, it's not broken. The kadmin server that's active responds to the
request. If my admin server goes down I can "promote" one of the slaves.

> True, but modern hardware can handle VERY VERY large numbers of clients.
> krb5 requests are short and efficient for the most part.  You shouldn't
> need more than 3 IPs and you can even have them on 2 servers (reserving
> the 3rd for future use if you don't want to maintain the extra HW).
> 
> If you use DNS SRV records you can also add new systems without client
> config change.  That's what we do.

I can't modify DNS.

> The load balancer is simply another failure point.

As is everything else.

> /fc

-- 
Jason T Hardy
Unix Systems Administrator
Office of Information Technology
University of Texas at Arlington

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post