Re: Issues with sasl under heavy load, configuration issue?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Howard Chu wrote:
Paul Hasenohr wrote:

I am running Debian Etch with current Debian packages:
    * slapd 2.3.30-5
    * sasl2-bin 2.1.22.dfsg1-8
    * libsasl2-2 2.1.22.dfsg1-8
    * krb5-kdc 1.4.4-7etch5

Could anyone please tell me if this behaviour is to be expected or how
this could be improved?

Best advice - use Heimdal Kerberos. MIT Kerberos code quality is poor, and thread safety is still unproven.

And the sky is blue, and that has NOTHING to do with the problem.

The problem is _exactly_ what the log says it is. The client is sending multiple identical auth requests, which the KDC is (properly) rejecting as a replay attack. Google shows many hits for a similar bug in mod_auth_kerb.

--
Carson

[Index of Archives]     [Info Cyrus]     [Squirrel Mail]     [Linux Media]     [Yosemite News]     [gtk]     [KDE]     [Gimp on Windows]     [Steve's Art]

  Powered by Linux