Re: Binding to Directory Server with Kerberos Tickets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

I was just wondering if anyone had any thoughts on this... if not,
perhaps a recomendation for the best way to load balance a number of
replicas and still allow LDAP to bind using a Kerberos ticket?

Thanks!

Tim



Tim Hartmann wrote:
> Hi,
>
> I've been configuring our Directory Server implementation to use gss-api
> for authentication, and it works great! However I ran into a bit of a
> snag and was hoping someone on the list might have a suggestion for a
> resolution!
>
> I followed the docs during my configuration and all went well
>
> http://www.redhat.com/docs/manuals/dir-server/ag/8.0/Introduction_to_SASL-Configuring_Kerberos.html
>
> I'm able to bind to our ldap replicas with my TGT when I search the real  hostname, however we load balance our replicas behind a Cisco SLB which serves out a second hostname and IP. 
>
> I've updated the ldap keytab file to include both the Kerberos principles for the real hostname, and the slb hostname, and am still able to sucessfully bind with Kerberos to the real hostname, but not through the SLB. 
>
> I had a similar problem with kerberized ssh a while back, and the solution there was a patch to openssh which allowed Kerberos to use any principle in the keytab file. (the GSSAPIStrictAcceptorCheck flag in ssh provides this)  Does FDS have any similar configuration option? Or had anyone run into this sort of issue while trying to bind to ldap via kerberos? 
>
> I'd also be willing to load balance the servers useing some other means beside the SLB. 
>
> Thanks!!
>
>
> Tim
>
>
>
>
>   




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux