[24999] in Kerberos
Re: Possible to use only IP addresses in MIT Kerberos (ie: disable
daemon@ATHENA.MIT.EDU (Brian Davidson)
Thu Nov 24 12:16:20 2005
Mime-Version: 1.0 (Apple Message framework v623)
In-Reply-To: <g3zmnuvi4l.fsf@sa.vix.com>
Content-Type: text/plain; charset=US-ASCII; format=flowed
Message-Id: <187344665a72c381391cdf4e2dd7b09d@gmu.edu>
Content-Transfer-Encoding: 7bit
From: Brian Davidson <bdavids1@gmu.edu>
Date: Thu, 24 Nov 2005 12:16:00 -0500
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
My understanding is that the process for determining what service
principal to obtain for a server involves doing gethostbyaddr(
gethostbyname() ). That is, find the IP for the given host, and then
find the name associated with that IP. Then ask the KDC for a ticket
for host/name.
So, you don't have to use DNS, but you must have resolvable names.
Brian
On Nov 23, 2005, at 10:28 PM, Paul Vixie wrote:
> rchowneltura@hotmail.com writes:
>
>> Has anybody had success in configuring only IP addresses
>> in MIT Kerberos5, or perhaps give me any tips?
>
> when i had to deploy krb5 without dns, i had to distribute an
> /etc/hosts file.
> --
> Paul Vixie
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos