[18956] in Kerberos_V5_Development
Re: How often does MIT krb5 request for KDC info through DNS?
daemon@ATHENA.MIT.EDU (Nico Williams)
Tue Aug 5 16:48:16 2014
MIME-Version: 1.0
In-Reply-To: <ldva97iitdd.fsf@sarnath.mit.edu>
Date: Tue, 5 Aug 2014 15:48:03 -0500
Message-ID: <CAK3OfOhnSa9MErrS78+R6uLw_E6wqqwqrrv-et8MxVikyuiRCQ@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Tom Yu <tlyu@mit.edu>
Cc: spike_white@dell.com, "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, Aug 5, 2014 at 3:17 PM, Tom Yu <tlyu@mit.edu> wrote:
> Nico Williams <nico@cryptonector.com> writes:
>
>> On Tue, Aug 5, 2014 at 2:50 PM, <Spike_White@dell.com> wrote:
>>> Doesn't "name service caching" via nscd solve this?
>>
>> nscd is specifically about Unix name services, lookups in the
>> hosts(4), passwd(4), ... DBs.
>>
>> We're talking about DNS SRV RR lookups though; nscd does nothing about those.
>
> I thought the A and AAAA lookups for the addresses of 30+ KDCs were what
> were at issue here, unless I'm misunderstanding something.
Ah, those would get cached by nscd, yes.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev