[23250] in Kerberos

home help back first fref pref prev next nref lref last post

Kerberos authentication on multi-homed servers

daemon@ATHENA.MIT.EDU (Matthew Willis)
Mon Jan 24 18:06:13 2005

Mime-Version: 1.0 (Apple Message framework v619)
Content-Transfer-Encoding: 7bit
Message-Id: <5CAFC2B0-6E5C-11D9-983A-000A95AE4346@ecornell.com>
Content-Type: text/plain; charset=US-ASCII; format=flowed
To: kerberos@mit.edu
From: Matthew Willis <mwillis@ecornell.com>
Date: Mon, 24 Jan 2005 18:04:55 -0500
Errors-To: kerberos-bounces@mit.edu

I have a question on how folks are dealing with using Kerberos on 
multi-homed servers, where each NIC has a different hostname.

For example, imagine a server with a "front-end" NIC connected to the 
Internet (server.domain.foo), and a "back-end" NIC on the backup 
network (server-backup.internal.domain.foo)/
If I want to ssh into the server via the back-end NIC, how can I copy 
the existing "host/server.domain.foo@REALM.FOO" principal to also 
handle "host/server-backup.internal.domain.foo@REALM.FOO" in 
krb5.keytab?

-lilmatt

(Sorry for the repost, but the previous message erroneously referenced 
another thread.)
--
Matthew Willis
Information Technology
eCornell

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post