Kerberos Login Handler and multiple KDCs
Martin B. Smith
smithmb at ufl.edu
Tue Apr 3 19:02:42 BST 2012
Hi all,
We saw a very unusual situation the other day where we had a brief
outage on the first KDC that most clients at UF list in their
/etc/krb5.conf. We use the Kerberos LoginHandler, and our IdPs all
seamless switched to the 2nd KDC listed in krb5.conf. But... after the
first KDC recovered, we had something unexpected happen.
For some reason, we *still* see a couple of the IdPs in our cluster
using the KDC listed second in krb5.conf. They don't seem to have gone
back to the first KDC.
This is unusual, as we're not seeing any other clients acting this way
that use krb5 libs. I'm also unable to reproduce this behavior with a
trivial Java program that continuously exercises Krb5LoginModule for
JAAS. My trivial example will correctly fail back to the first KDC every
time it becomes available again.
I'm hoping the authors of the Kerberos LoginHandler or other developers
might be able to speculate as to the reasons why I'd see this "stuck on
the 2nd KDC" behavior before I go digging through the LoginHandler and
reproducing the issue directly in the IdP itself. It seems that right
now, the only resolution is to restart the container.
Thanks in advance for any insight.
--
Martin B. Smith
smithmb at ufl.edu - (352) 273-1374
CNS/Open Systems Group
University of Florida
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4893 bytes
Desc: S/MIME Cryptographic Signature
Url : http://shibboleth.net/pipermail/users/attachments/20120403/6e50d789/attachment.bin
More information about the users
mailing list