[18943] in Kerberos_V5_Development
Re: How often does MIT krb5 request for KDC info through DNS?
daemon@ATHENA.MIT.EDU (Brandon Allbery)
Tue Aug 5 10:45:04 2014
From: Brandon Allbery <ballbery@sinenomine.net>
To: "krbdev@mit.edu" <krbdev@mit.edu>
Date: Tue, 5 Aug 2014 14:44:54 +0000
Message-ID: <1407249894.13485.4.camel@vikktakkht.kf8nh.com>
In-Reply-To: <53E0E7F8.701@mit.edu>
Content-Language: en-US
Content-ID: <1D0F0FB6ED53EA4FA3C952F8465CD049@mex05.mlsrvr.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, 2014-08-05 at 10:19 -0400, Greg Hudson wrote:
> That said, if the popular platforms aren't interested in providing
> this
> service, at some point applications have to step in and solve the
> problem even if it's not optimal. We might add some amount of DNS
> caching in libkrb5 at some point (with a very low internal TTL),
> though
> it isn't super high on the priority list.
Browsers do this these days. And balancing faster performance due to
local caching against correct operation took them a while. It's
something of a mess; it really does not belong in the application, as
you noted.
--
brandon s allbery kf8nh sine nomine associates
allbery.b@gmail.com ballbery@sinenomine.net
unix openafs kerberos infrastructure xmonad http://sinenomine.net
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev