You may need a third entry in the keytab for the VIP. IE will look for a
HTTP/<vip> ticket.
Regards
Markus
"brendan" <bpk678@xxxxxxxxx> wrote in message
news:1346159765625-4656345.post@xxxxxxxxxxxxx...
i have two squid instances on two separate servers. each is configured
with
kerberos auth, and when i point at one or the other, the kerberos auth
works
fine. when i point to a load balanced VIP, the auth does not work. i
found
the below and tried the method using the one keytab file for both
instances
and the -s GSS_C_NO_NAME option in the conf file. this did not work as
expected.
the load balancing process i am using is the "balance" package for fedora
16. it does a SNAT on all requests it handles. could this be part of why
i
am having issues? i found a couple of packages that i might be able to
use
for load balancing in the repos, balance, ipvsadm and haproxy. does
anyone
have experience/success with any of these or might one be recommended over
the others?
--
View this message in context:
http://squid-web-proxy-cache.1019090.n4.nabble.com/Help-with-Kerberos-Configuration-tp4076779p4656345.html
Sent from the Squid - Users mailing list archive at Nabble.com.