[18955] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: How often does MIT krb5 request for KDC info through DNS?

daemon@ATHENA.MIT.EDU (Tom Yu)
Tue Aug 5 16:17:27 2014

From: Tom Yu <tlyu@mit.edu>
To: Nico Williams <nico@cryptonector.com>
Date: Tue, 05 Aug 2014 16:17:18 -0400
In-Reply-To: <CAK3OfOhZCSatOJudQbzfHOwuL=MYOX=c7qquO83E+McuuvgbbQ@mail.gmail.com>
	(Nico Williams's message of "Tue, 5 Aug 2014 15:04:55 -0500")
Message-ID: <ldva97iitdd.fsf@sarnath.mit.edu>
MIME-Version: 1.0
Cc: spike_white@dell.com, "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Nico Williams <nico@cryptonector.com> writes:

> On Tue, Aug 5, 2014 at 2:50 PM,  <Spike_White@dell.com> wrote:
>> Doesn't "name service caching"  via nscd solve this?
>
> nscd is specifically about Unix name services, lookups in the
> hosts(4), passwd(4), ... DBs.
>
> We're talking about DNS SRV RR lookups though; nscd does nothing about those.

I thought the A and AAAA lookups for the addresses of 30+ KDCs were what
were at issue here, unless I'm misunderstanding something.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post