[27567] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Reading kerberos-adm from DNS: when will MIT-krb support this?

daemon@ATHENA.MIT.EDU (Ken Raeburn)
Mon Mar 12 17:48:33 2007

In-Reply-To: <200703120511.AAA11265@quince.ifs.umich.edu>
Mime-Version: 1.0 (Apple Message framework v752.2)
Message-Id: <1E393FB5-8557-4BBE-8896-5FCE67A6F41D@mit.edu>
From: Ken Raeburn <raeburn@mit.edu>
Date: Mon, 12 Mar 2007 17:48:05 -0400
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Mar 12, 2007, at 1:11, Marcus Watts wrote:
> cpkrb0703@melvex.xs4all.nl writes:
>> Date: Sun, 11 Mar 2007 22:24:44 +0100
>> From: Bastian <cpkrb0703@melvex.xs4all.nl>
>> To: kerberos@mit.edu
>> Subject: Reading kerberos-adm from DNS: when will MIT-krb support  
>> this?
>>
>> Hi,
>>
>> In the release notes I read that in the future, MIT kerberos will be
>> able to read the name of the administrative server from DNS (through
>> kerboros-adm). Does anyone know when this is going to be implemented?
>>
>> MIT kerberos already implements the use of the other kerberos related
>> DNS records, but kerberos-adm still requires a local krb5.conf
>>
>> Bastian
>
> I believe the future has already arrived.  Current MIT code should
> be capable of finding and using records like this:
>
> 	spam% dig _kerberos-adm._tcp.umich.edu srv

This is used for the password-changing service, but unfortunately the  
RPC code used for the kadmin program still looks up admin_server, and  
uses the first IP address found when looking up that hostname.  No  
DNS, one hostname, one address, no service-location plugin support,  
no IPv6.  These do need to be fixed....

Ken


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post