Kerberos Login Handler and multiple KDCs

Martin B. Smith smithmb at ufl.edu
Tue Apr 3 19:02:42 BST 2012


Hi all,

We saw a very unusual situation the other day where we had a brief 
outage on the first KDC that most clients at UF list in their 
/etc/krb5.conf. We use the Kerberos LoginHandler, and our IdPs all 
seamless switched to the 2nd KDC listed in krb5.conf. But... after the 
first KDC recovered, we had something unexpected happen.

For some reason, we *still* see a couple of the IdPs in our cluster 
using the KDC listed second in krb5.conf. They don't seem to have gone 
back to the first KDC.

This is unusual, as we're not seeing any other clients acting this way 
that use krb5 libs. I'm also unable to reproduce this behavior with a 
trivial Java program that continuously exercises Krb5LoginModule for 
JAAS. My trivial example will correctly fail back to the first KDC every 
time it becomes available again.

I'm hoping the authors of the Kerberos LoginHandler or other developers 
might be able to speculate as to the reasons why I'd see this "stuck on 
the 2nd KDC" behavior before I go digging through the LoginHandler and 
reproducing the issue directly in the IdP itself. It seems that right 
now, the only resolution is to restart the container.

Thanks in advance for any insight.
--
Martin B. Smith
smithmb at ufl.edu - (352) 273-1374
CNS/Open Systems Group
University of Florida

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4893 bytes
Desc: S/MIME Cryptographic Signature
Url : http://shibboleth.net/pipermail/users/attachments/20120403/6e50d789/attachment.bin 


More information about the users mailing list