[23212] in Kerberos
Re: Kerberos authentication without reverse lookup
daemon@ATHENA.MIT.EDU (Rachel Elizabeth Dillon)
Mon Jan 17 16:49:18 2005
Date: Mon, 17 Jan 2005 16:49:14 -0500
From: Rachel Elizabeth Dillon <red@mit.edu>
To: Fredrik Tolf <fredrik@dolda2000.com>
Message-ID: <20050117214914.GT18360@yiff.mit.edu>
Mime-Version: 1.0
In-Reply-To: <1105933259.1924.60.camel@pc7>
cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============5808455692661495=="
Errors-To: kerberos-bounces@mit.edu
--===============5808455692661495==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="CC7kGhlJjTyMjSRG"
Content-Disposition: inline
--CC7kGhlJjTyMjSRG
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Mon, Jan 17, 2005 at 04:40:59AM +0100, Fredrik Tolf wrote:
> I was thinking about adding local hints to our own reverse zones to our
> Bind configs to make reverse lookups work just between our own networks,
> but that will be extremely difficult at best, since he has a dynamic IP.
> We can figure out how to update the forward zones when his IP changes,
> but since updating the reverse zones involves creating an entire new
> zone each time, that solution feels a bit hopeless... :-(
Making a new zone is not particularly harder than updating an existing
sone. It will lead to a bunch of useless reverse zone files, but you could
write a script to clean those up too. I am assuming that you are running
your own DNS servers here; if not, I am not sure what you would do. If
you are running your own DNS server, you still have to tread carefully=20
when making yourself the primary source of reverse DNS information, but
I think you should be able to do it. (You should even be able to set up
something that does the updates automatically; I would use Net::DNS in=20
Perl to do this, but I am sure there are plenty of fine solutions.)
=20
> So, is there anyone who has experienced a similar situation before and
> solved it? Is there, by any chance, another way of letting Kerberos
> canonicalize service principal names?
I've never had to deal with this personally, nor do I know of another way=
=20
to canonicalize service principal names; I just happen to have been doing
a lot of work with DNS recently. :)=20
Best of luck,
-r.
--CC7kGhlJjTyMjSRG
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFB7DLarAG/UVUP/b0RAmjEAKC1J968pqQaP+1Zd1F+vjNLuYbeigCdF/jZ
XhhwEp9CFUw7v7U3aZOIMdI=
=pAvv
-----END PGP SIGNATURE-----
--CC7kGhlJjTyMjSRG--
--===============5808455692661495==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
--===============5808455692661495==--