kerberos password change in master-slave environ

Subu Ayyagari s.ayyagari at xpedite.com
Wed Mar 24 10:43:28 EST 2004


All,

I have a kerberos master-slave (1 master, 4 slaves) environment.
When user changes password, master has the recent passwd while
the slaves have older password until kerberos database is propagated
(once in 5 hrs).

I have configured all clients/member unix servers so that they query
the slaves.

Problem: When user changes password the new password is unusable
         until krb5 database is propagated.

Question: If a user changes password (using kpasswd), shouldn't the slave
           kerberos server check with master if it has a more recent copy
           of the password?

         Is there a more elegant solution, than say propagating corporate
wide
         kerberos database every 5 min or so ?

thanks
-subu





More information about the Kerberos mailing list