[29718] in Kerberos

home help back first fref pref prev next nref lref last post

Is it necessary to assign hostname to slave KDC in small letters

daemon@ATHENA.MIT.EDU (Juri Dakua)
Wed Apr 23 10:54:43 2008

Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Wed, 23 Apr 2008 20:21:43 +0530
Message-ID: <089781E831473740B23334AE52636CD30F578A1B@SINBNGEX001.TechMahindra.com>
In-Reply-To: <47A348A0.3040104@espci.fr>
From: "Juri Dakua" <jdakua@TechMahindra.com>
To: <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu


Asper Kerberos V5 Installation Guide, it sounds like
Database propagation works using the host principal of the slave KDC.
I have assigned the hostname of the slave KDC as TESTSLAVE having domain
name as techmbng.com and created the host principal as
host/TESTSLAVE.techmbng.com. My DNS server also returns
TESTSLAVE.techmbng.com on IP address lookup. 

However the database propagation from master KDC fails giving the error

kprop: Server not found in Kerberos database while getting initial
ticket

On the other hand, keeping all configurations same and just creating the
host principal as host/testslave.techmbng.com rather than
host/TESTSLAVE.techmbng.com, makes database propagation succeed. 

FYI: all goes well if I assign the hostname in small letters
(testslave), create the host principal accordingly
(host/testslave.techmbng.com) and configure DNS server to return the
same on IP lookup (testslave.techmbng.com).

>From this it seems like kprop tries to do database propagation using the
host principal for the FQDN with hostname in all small letters
(testslave.techmbng.com) rather than the actual FQDN assigned.

Is it mandatory to have to slave KDC hostname assigned with all small
letters or am I missing something? 


Thanks
Juri

============================================================================================================================
 
Disclaimer:

This message and the information contained herein is proprietary and confidential and subject to the Tech Mahindra policy statement, you may review the policy at <a href="http://www.techmahindra.com/Disclaimer.html">http://www.techmahindra.com/Disclaimer.html</a> externally and <a href="http://tim.techmahindra.com/Disclaimer.html">http://tim.techmahindra.com/Disclaimer.html</a> internally within Tech Mahindra.

============================================================================================================================

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post