Re: Kerberos KDC

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



LDAP is easier to DOS that kerberos.
I've seen instances with OpenLDAP where bad code in a web app caused clusters of LDAP servers to run out of connections but the kerberos servers stayed up so none of the users noticed because of SSSD and or nscd had the data from the LDAP servers cached‎. In those instances keeping the kerberos servers separate saved the day, because if they had shared their database it would have locked out all of the users.


From: Joshua Brodie
Sent: Friday, September 25, 2015 15:36
To: General discussion list for the 389 Directory server project.
Reply To: General discussion list for the 389 Directory server project.
Subject: [389-users] Kerberos KDC

Hi All:

On a large 389 implementation - where downtime is not an option - are there pros/cons to having the KDC on same server as 389 (sharing the database) - or having the KDC on separate, redundant, servers?

Thanks.

--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users

[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux