[22937] in Kerberos

home help back first fref pref prev next nref lref last post

kerberos in load balanced environment: host name/dns issue

daemon@ATHENA.MIT.EDU (Pitrich, Karl)
Tue Nov 30 05:47:07 2004

From: "Pitrich, Karl" <karl.pitrich@fabasoft.com>
To: kerberos@mit.edu
Message-Id: <1101811433.25286.417.camel@zaphod>
Mime-Version: 1.0
Date: Tue, 30 Nov 2004 11:43:53 +0100
Content-Type: multipart/mixed; boundary="===============42722878293870492=="
Errors-To: kerberos-bounces@mit.edu


--===============42722878293870492==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="=-6Sd5t2uEX/SjOHmjX2oV"


--=-6Sd5t2uEX/SjOHmjX2oV
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Hi,

we're using Apache mod_spnego with krb1.3.5 to fake M$ Integrated login
to Windows clients from a Linux server environment.
This works fine using single a single server.

Now we're testing multiple loadbalanced webservers.
To make such a setup work, we need to set each webserver's hostname to
the dns name of the load balancer, for the krb libs to use dns correctly
and gernerate the valid principal name.
This, of course, imposes at least administrative difficulties.

- how should this problem be addressed in a sane manner?

- would you, for example, accept a patch adding an environment variable
  or configuration option  that contains the required (faked, that is)
  hostname (of the loadbalancer), which is then taking precedence over
  gethostname(2) used in the krb libs?


thanks,

 / karl



--=-6Sd5t2uEX/SjOHmjX2oV
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQBBrE7phjEylB2OKukRAlM5AKC9KZfFaaJC/NV8+fJrdUeMBSkWwgCeLbUi
JfGw/565TaUEEYTmVu6dq5Y=
=ZBUg
-----END PGP SIGNATURE-----

--=-6Sd5t2uEX/SjOHmjX2oV--

--===============42722878293870492==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============42722878293870492==--

home help back first fref pref prev next nref lref last post